-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 13 Jul 2018 13:05:13 +0200 Source: cups Binary: libcups2 libcupsimage2 libcupscgi1 libcupsmime1 libcupsppdc1 cups cups-core-drivers cups-daemon cups-client libcups2-dev libcupsimage2-dev libcupscgi1-dev libcupsmime1-dev libcupsppdc1-dev cups-bsd cups-common cups-server-common cups-ppdc cups-dbg Architecture: source amd64 all Version: 1.7.5-11+deb8u4 Distribution: jessie-security Urgency: medium Maintainer: Debian Printing Team <debian-printing@lists.debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Description: cups - Common UNIX Printing System(tm) - PPD/driver support, web interfa cups-bsd - Common UNIX Printing System(tm) - BSD commands cups-client - Common UNIX Printing System(tm) - client programs (SysV) cups-common - Common UNIX Printing System(tm) - common files cups-core-drivers - Common UNIX Printing System(tm) - PPD-less printing cups-daemon - Common UNIX Printing System(tm) - daemon cups-dbg - Common UNIX Printing System(tm) - debugging symbols cups-ppdc - Common UNIX Printing System(tm) - PPD manipulation utilities cups-server-common - Common UNIX Printing System(tm) - server common files libcups2 - Common UNIX Printing System(tm) - Core library libcups2-dev - Common UNIX Printing System(tm) - Development files CUPS library libcupscgi1 - Common UNIX Printing System(tm) - CGI library libcupscgi1-dev - Common UNIX Printing System(tm) - Development files for CGI libra libcupsimage2 - Common UNIX Printing System(tm) - Raster image library libcupsimage2-dev - Common UNIX Printing System(tm) - Development files CUPS image li libcupsmime1 - Common UNIX Printing System(tm) - MIME library libcupsmime1-dev - Common UNIX Printing System(tm) - Development files MIME library libcupsppdc1 - Common UNIX Printing System(tm) - PPD manipulation library libcupsppdc1-dev - Common UNIX Printing System(tm) - Development files PPD library Changes: cups (1.7.5-11+deb8u4) jessie-security; urgency=medium . * Non-maintainer upload by the LTS team. * CVE-2018-4180: Local Privilege Escalation to Root in dnssd Backend (CUPS_SERVERBIN) CVE-2018-4181: Limited Local File Reads as Root via cupsd.conf Include Directive - Backported patch taken from Ubuntu. * CVE-2018-6553: Fix AppArmor cupsd sandbox bypass due to use of hard links Checksums-Sha1: cf741b37b2ce0f243e6aa0487440baac9c311bf3 3635 cups_1.7.5-11+deb8u4.dsc 7cd1a18fe2988b4375e9276af313a53e1caf5a27 8793338 cups_1.7.5.orig.tar.bz2 523c3a2526e005f4de7e758587baf36f49fa0f49 306240 cups_1.7.5-11+deb8u4.debian.tar.xz 67f6632fd495d4428f7f9aab2163a3fbb72e6155 283674 libcups2_1.7.5-11+deb8u4_amd64.deb 0721b728fa31af93100ea3d41a0151fa76e67cc0 117010 libcupsimage2_1.7.5-11+deb8u4_amd64.deb 2a92c5bba94d4f9b62bc96750dd6e0078f8de1b8 128080 libcupscgi1_1.7.5-11+deb8u4_amd64.deb edf195753f65c3b619f884b9044e1853cab11cb4 114060 libcupsmime1_1.7.5-11+deb8u4_amd64.deb f8d600250be178eda74b35724c2098300a8e579c 146052 libcupsppdc1_1.7.5-11+deb8u4_amd64.deb 8d73ed9ee26e044ed63c79e9cf57fe5a85cb96e5 290368 cups_1.7.5-11+deb8u4_amd64.deb 00d15727f8fb994df2f395a696489a03755e37c2 126732 cups-core-drivers_1.7.5-11+deb8u4_amd64.deb d07de14ca410bffbc2d28d27de7a9621c3485953 376906 cups-daemon_1.7.5-11+deb8u4_amd64.deb fd74847fc5182c769446e285a633c2e35a3a8206 299374 cups-client_1.7.5-11+deb8u4_amd64.deb f8d170cce65197c0edcc75dce6cf324c1ed6e3da 321260 libcups2-dev_1.7.5-11+deb8u4_amd64.deb 4f61ad38ed6997344f390a062c3bdfc305f8fff8 18036 libcupsimage2-dev_1.7.5-11+deb8u4_amd64.deb 7746c4d9a9f9f129d79ee1637a88ed7981c93b9c 130674 libcupscgi1-dev_1.7.5-11+deb8u4_amd64.deb c0714f7fe203bf0f7e2b3ab3393706b364fdd9c3 114816 libcupsmime1-dev_1.7.5-11+deb8u4_amd64.deb 5751237c46001e0c3b9b32d2e5a5133b4974b9ae 151152 libcupsppdc1-dev_1.7.5-11+deb8u4_amd64.deb eb7d3240e9da3fc6ec9873c3b70209e14cb291c9 35378 cups-bsd_1.7.5-11+deb8u4_amd64.deb 32e2b318e7aabb57c0c6dc53c3860c675caf0408 273768 cups-common_1.7.5-11+deb8u4_all.deb bcf84640e65c3ad410f418a2ad1aab898a5b1ade 620272 cups-server-common_1.7.5-11+deb8u4_all.deb 3eb64f23e0fbe4d5059500ea8a20efa8cb135801 126678 cups-ppdc_1.7.5-11+deb8u4_amd64.deb b35470cebd09680dbebd38518b2a3cf1593fa711 1739442 cups-dbg_1.7.5-11+deb8u4_amd64.deb Checksums-Sha256: 8e3a10a9310de07bef2595ca313cd429e14625641b06443a40e144f5e01b4c67 3635 cups_1.7.5-11+deb8u4.dsc 18cb4c6847dbaaaa05c8b35af787f19dd5c7686970b46548e72c711c6f26bd02 8793338 cups_1.7.5.orig.tar.bz2 fd85f86511e017f5eae28b310cb8807155c29cc48ce427030b00c75084aa58a4 306240 cups_1.7.5-11+deb8u4.debian.tar.xz 3b8a0320c839c2f7afaff039f9687a24fbaf0a892e0e16c644ef5256f6960366 283674 libcups2_1.7.5-11+deb8u4_amd64.deb 87fd061b0e62eceec429193cf89285464ee6c3b1ad244a47a69801134d3e7fb9 117010 libcupsimage2_1.7.5-11+deb8u4_amd64.deb d234115bbdeb9c91866542b4646814a7b59c171ee46ed15fb22e484f64eec5ae 128080 libcupscgi1_1.7.5-11+deb8u4_amd64.deb 91b4c2a9199b7368f4d85cb84b9aeef82eba0abe4b9c63b046610a636e0b524b 114060 libcupsmime1_1.7.5-11+deb8u4_amd64.deb 3439e9cb4f0bcb4d573b5716f488ecd316fcd811bb373b4e871c1962ae8606f6 146052 libcupsppdc1_1.7.5-11+deb8u4_amd64.deb dea5aaa93e52caf42706b7cb49041388532422354dc948ff87bb9240aab8b74a 290368 cups_1.7.5-11+deb8u4_amd64.deb 64e3330721598ba52f8bdca7935f4c36a3a4199ca9ec92c58db305badc17c26e 126732 cups-core-drivers_1.7.5-11+deb8u4_amd64.deb cb19efff4ba16f80c3d6c91896ca301d537f5c7086b09ebb97f5496841b0fcdb 376906 cups-daemon_1.7.5-11+deb8u4_amd64.deb 343a86c0cb578a1f716c4ec3de813f96fb2fbb681a05004173033a19f8bd52c8 299374 cups-client_1.7.5-11+deb8u4_amd64.deb 0b485a863628e6c048882a8cf83dad40604d8b5c5e878614928b952516e27030 321260 libcups2-dev_1.7.5-11+deb8u4_amd64.deb 1e3c06b9553561217a742b6666ddac638db4d4edd8be57e35d5aa9badeada226 18036 libcupsimage2-dev_1.7.5-11+deb8u4_amd64.deb d670a06a9d33b2e112b6f3970fa7857cd33627d349f5ab2ae0d6da440b94b5a4 130674 libcupscgi1-dev_1.7.5-11+deb8u4_amd64.deb 43b2e69f2c5ec034d65b231e96908e0bbc79e4b5184e21bdf9b3e0ef67c9951d 114816 libcupsmime1-dev_1.7.5-11+deb8u4_amd64.deb f05010806769e69b7c5ea25a6d07c631b6109c8211394df66d309859c8b91578 151152 libcupsppdc1-dev_1.7.5-11+deb8u4_amd64.deb 0d287551200ae13aa7e19386ad18a9c745f71fbf86b48c8d49c22d87bc09173c 35378 cups-bsd_1.7.5-11+deb8u4_amd64.deb 0b8efcbfaf4d889ec79622857c8b41f5c452afa9c7203174a763d8fcf58a1b64 273768 cups-common_1.7.5-11+deb8u4_all.deb 7477ae367d0b7f8b3b2edf0bcb95e0f41d9c90587903655b7757248a86531c28 620272 cups-server-common_1.7.5-11+deb8u4_all.deb 2043e7f871e1ac4d2071801dd2541342734d3829691e83b21b47ca30d24434e3 126678 cups-ppdc_1.7.5-11+deb8u4_amd64.deb 2ec4180664c05f1c396a48232020919a5f144b098332dfbfb08dfbce0cc9fbe1 1739442 cups-dbg_1.7.5-11+deb8u4_amd64.deb Files: 27c6eab4f37add1655982b73a9f74044 3635 net optional cups_1.7.5-11+deb8u4.dsc 5d893edc2957005f78e2b2423fdace2e 8793338 net optional cups_1.7.5.orig.tar.bz2 6ec894c0e1054ff212663564a7daddb6 306240 net optional cups_1.7.5-11+deb8u4.debian.tar.xz 5cb8f27a8dd192f39a74e8f08501a515 283674 libs optional libcups2_1.7.5-11+deb8u4_amd64.deb e6caddc27a2e27ea6f00c615024bad20 117010 libs optional libcupsimage2_1.7.5-11+deb8u4_amd64.deb 01f67d19162fc282cb8d7f590a2ab34a 128080 libs optional libcupscgi1_1.7.5-11+deb8u4_amd64.deb a9f7ce436abba8ddeeb3785428976ea1 114060 libs optional libcupsmime1_1.7.5-11+deb8u4_amd64.deb 213a65f662b5c2a725579b501b76131c 146052 libs optional libcupsppdc1_1.7.5-11+deb8u4_amd64.deb b15c808ff2b2a846afa631c11ae8c343 290368 net optional cups_1.7.5-11+deb8u4_amd64.deb d596a74dc84b0420ec261e416511848f 126732 net optional cups-core-drivers_1.7.5-11+deb8u4_amd64.deb e459e4aca4a382c291b405a3acf95218 376906 net optional cups-daemon_1.7.5-11+deb8u4_amd64.deb 71c965f4690529518be3a4aa0f6489b0 299374 net optional cups-client_1.7.5-11+deb8u4_amd64.deb fac813afb060bdaada3f61ca30172ff3 321260 libdevel optional libcups2-dev_1.7.5-11+deb8u4_amd64.deb 6ee27ef5c223fd395a1f8416db92510c 18036 libdevel optional libcupsimage2-dev_1.7.5-11+deb8u4_amd64.deb 4c362ee08d32c12f5c1f94c690cb6c8b 130674 libdevel optional libcupscgi1-dev_1.7.5-11+deb8u4_amd64.deb ffe0ab82cf0722eaee254a586b26687b 114816 libdevel optional libcupsmime1-dev_1.7.5-11+deb8u4_amd64.deb 69365fb9bd48ff902b4a91555d64138e 151152 libdevel optional libcupsppdc1-dev_1.7.5-11+deb8u4_amd64.deb 83efe97c7d21af4f38231337ea27c2db 35378 net extra cups-bsd_1.7.5-11+deb8u4_amd64.deb 0d607921cd65f6b5eb22466e894fb325 273768 net optional cups-common_1.7.5-11+deb8u4_all.deb f003641830bf7145437aca9995c00415 620272 net optional cups-server-common_1.7.5-11+deb8u4_all.deb 86c53584ec05f1d6476df4fe27c3ebf5 126678 utils optional cups-ppdc_1.7.5-11+deb8u4_amd64.deb 6fa262befbca227ec270a096b56a9e5e 1739442 debug extra cups-dbg_1.7.5-11+deb8u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAltJwWEACgkQnUbEiOQ2 gwKIEw/+NSp3EdFToz/tdgoXs9g6dszmX4i1qUzS2jVFQVTDlnB8SMIfUz3Jkuly wlTZO10jyGZ8TgjyiBvuWOJbG3rMDlKf4dpo1kj7H/ddKmAUFXqIgUhXczuQMW6q KKHecwvDELnJ1jpm75tTt4x1M+BF/B4yQM/Batp0aia5loXYcxP0JfjfQYYCSvPc FKYuX4PAX9bGhguxqR9OU2KYr9EGs/RgmQxp6uUMQPS5PEXcPvsQUyvX/6WmDZs5 KSAPDFEMheOgtJZE+fhO992ZLPryKFAuapR8LlTfRMm4PmgMLRmkPJYo8SxoyzUT 6D/FvLtV5PzxEE1YlPBFcQZT7oze9yXJzFMNYRjAkAZyx1DmPvdRjemqKgTZSi8t bEjdZYIr1MRX8mTJAsa/E1c189YwAVJULD8dhwEMpnhfmVZZMO4rToINEVkFnrl0 16RR2PLrtgNwAEtrXW3ousUhg7Gdv2QZS35TjsUG74d2Z2z87Cb/xMeuRPUEIuQK noAEz6VEE9YdxHW3eS2pibvyXnXFt49kZBo+Hbm6I4A6YeU3BXKpm5Seyz+9X1wI qSwQ/QMVbepNWtr2h4HypiNqfdM4LBP+NSjrDF9BwSUmBI4Vtt9JLwXBei6h+tLV AovbFcS/vEWCmvtpeInOhE+qE0ej+KajZnqX0iYQi90dRYdN0Tk= =8Sud -----END PGP SIGNATURE-----