-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.6 Date: Fri, 17 Jan 2003 13:50:33 -0500 Source: cupsys Binary: cupsys-bsd libcupsys1 cupsys libcupsys1-dev Architecture: i386 Version: 1.0.4-12.1 Distribution: oldstable-security Urgency: high Maintainer: Debian/i386 Build Daemon Description: cupsys - Common UNIX Printing System(tm) - base cupsys-bsd - Common UNIX Printing System(tm) - BSD commands libcupsys1 - Common UNIX Printing System(tm) - libs libcupsys1-dev - Common UNIX Printing System(tm) - development files Changes: cupsys (1.0.4-12.1) oldstable-security; urgency=high . * Security team NMU * Fix bugs reported in iDEFENSE advisory http://www.idefense.com/advisory/12.19.02.txt - [issue 1] patch integer overflows in image handling code (filter/image-*.c) - [issue 2] not applicable to this version - [issue 3] check for invalid URIs in browse packets (scheduler/dirsvc.c) - [issue 4] protect against negative length memcpy calls (scheduler/client.c, cups/http.c) - [issue 5] fix unsafe strncat calls (scheduler/job.c) - [issue 6] add check for zero-{width,height} GIF image (filter/image-gif.c) - [issue 7] detect errors and close file descriptors appropriately (scheduler/client.c) * Fix other instances of incorrect strncat usage (scheduler/client.c, scheduler/dirsvc.c, scheduler/log.c) * Include additional fixes from Debian maintainer, Jeff Licquia - Recover from file descriptor DoS more gracefully - Fix from upstream to return status indicating whether CloseClient was called, to prevent further processing - add missing CloseClient call which caused DoS to be re-introduced by above patch Files: 3e977f66990a5d169d24088c22ffba34 2295330 net extra cupsys_1.0.4-12.1_i386.deb 9db4d79646e4e69a763f9f73d87124a1 64790 net extra libcupsys1_1.0.4-12.1_i386.deb d62c83955dfb01d44c95a4e0066f4760 83146 net extra libcupsys1-dev_1.0.4-12.1_i386.deb d101cceb0b1929b21e8fa16b688b43aa 16746 net extra cupsys-bsd_1.0.4-12.1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE+KlX2W5ql+IAeqTIRAhXIAKCV+h+kdlIkwBOCTB9fpg18gG3xCQCgrZ9e k0r6LKziVgPFydsr7Bd/EvY= =P7rm -----END PGP SIGNATURE-----