Package "cups"

Name: cups


Common UNIX Printing System(tm) - PPD/driver support, web interface

Latest version: 2.2.4-7ubuntu3.1
Release: artful (17.10)
Level: updates
Repository: main
Homepage: https://www.cups.org/


Save this URL for the latest version of "cups": https://www.ubuntuupdates.org/cups

Download "cups"

Other versions of "cups" in Artful

Repository Area Version
base main 2.2.4-7ubuntu2
security main 2.2.4-7ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Version: 2.2.4-7ubuntu3.1 2018-07-11 18:07:30 UTC

  cups (2.2.4-7ubuntu3.1) artful-security; urgency=medium

  * SECURITY UPDATE: scheduler crash via DBUS notifications
    - debian/patches/CVE-2017-18248.patch: validate requesting-user-name in
    - CVE-2017-18248
  * SECURITY UPDATE: privilege escalation in dnssd backend
    - debian/patches/CVE-2018-418x.patch: don't allow PassEnv and SetEnv to
      override standard variables in man/cups-files.conf.man.in,
      man/cupsd.conf.man.in, scheduler/conf.c, test/run-stp-tests.sh.
    - CVE-2018-4180
  * SECURITY UPDATE: local file read via Include directive
    - debian/patches/CVE-2018-418x.patch: remove Include directive handling
      in scheduler/conf.c.
    - CVE-2018-4181
  * SECURITY UPDATE: AppArmor sandbox bypass
    - debian/local/apparmor-profile: also confine
    - CVE-2018-6553

 -- Marc Deslauriers <email address hidden> Fri, 22 Jun 2018 13:41:03 -0400

Source diff to previous version
CVE-2017-18248 The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs
CVE-2018-4180 Local Privilege Escalation to Root in dnssd Backend (CUPS_SERVERBIN)
CVE-2018-4181 Limited Local File Reads as Root via cupsd.conf Include Directive
CVE-2018-6553 AppArmor profile issue in cups

Version: 2.2.4-7ubuntu3 2017-11-20 17:06:44 UTC

  cups (2.2.4-7ubuntu3) artful; urgency=medium

  * Fixes cupsGetNamedDest not using local default printer
    (LP: #1729910)

 -- Dariusz Gadomski <email address hidden> Wed, 08 Nov 2017 11:31:52 +0100

1729910 lp ignores ~/.cups/lpoptions in 17.10

About   -   Send Feedback to @ubuntu_updates