cups
33
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
cscope is a mature, ncurses-based, C source-code tree browsing tool.
Multiple buffer overflow flaws were found in cscope. An attacker could create a specially crafted
source code file that could cause cscope to crash or, possibly, execute arbitrary code when browsed
with cscope. (
CVE-2004-2541
203
,
CVE-2009-0148
204
)
All users of cscope are advised to upgrade to this updated package, which contains backported
patches to fix these issues. All running instances of cscope must be restarted for this update to take
effect.
1.29. cups
1.29.1. RHBA-2009:1360: bug fix update
Updated cups packages that fix several bugs are now available.
The Common UNIX Printing System (CUPS) provides a portable printing layer for UNIX and Unix-like
operating systems.
These updated packages address the following bugs:
• the libcups library's HTTP state machine could get into a busy loop when a connection was closed
at an unexpected point. (BZ#474323)
• web interface template files and translated template files were not marked as configuration files
so local modifications to them would be lost when applying updates. This update will also cause
local modifications to those files to be lost, but will prevent the same situation occurring with future
updates. (BZ#474769)
• the "compression" job option was encoded with the wrong IPP tag, preventing the "document-
format" job option from overriding automatic MIME type detection of compressed job files .
(BZ#474814)
• the "mailto" CUPS notifier used the wrong line ending when transferring messages to an SMTP
server, causing it not to send any notifications. (BZ#474920)
• automatic MIME type detection would fail when the document name was required by the relevant
rule but only one file was present in the job. MIME detection would also fail with some rules using
"+" (e.g. application/x-shell). (BZ#479635)
• incorrect web interface URLs would be given when the server's domain name resolved to a local
loopback address on the server. (BZ#479809)
• the CUPS configuration file directive "Satisfy Any" was not correctly implemented, causing access to
be restricted in situations where it should not have been. (BZ#481303)
• an optimization in the libcups library for fetching details of a print queue when its name is known
caused problems with obtaining the name of the default printer when "lpoptions" files listed a non-
existent queue as the default. (BZ#481481)
203
https://www.redhat.com/security/data/cve/CVE-2004-2541.html
204
https://www.redhat.com/security/data/cve/CVE-2009-0148.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...