RHSA-2009:1513: Moderate: cups security update
The Common UNIX Printing System (CUPS) provides a portable printing layerfor UNIX operating systems. The CUPS "pdftops" filter converts PortableDocument Format (PDF) files to PostScript.Two integer overflow flaws were found in the CUPS "pdftops" filter. Anattacker could create a malicious PDF file that would cause "pdftops" tocrash or, potentially, execute arbitrary code as the "lp" user if the filewas printed. (CVE-2009-3608, CVE-2009-3609)Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608issue.Users of cups are advised to upgrade to these updated packages, whichcontain a backported patch to correct these issues. After installing theupdate, the cupsd daemon will be restarted automatically.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1513?
RHSA-2009:1513 is classified as a moderate severity vulnerability.
How do I fix RHSA-2009:1513?
To fix RHSA-2009:1513, update to CUPS version 1.3.7-11.el5_4.3 or later.
Which packages are affected by RHSA-2009:1513?
The affected packages include cups, cups-devel, cups-libs, and cups-lpd.
What type of vulnerability is addressed in RHSA-2009:1513?
RHSA-2009:1513 addresses integer overflow flaws in the CUPS 'pdftops' filter.
Is there a workaround for RHSA-2009:1513?
There is no specific workaround for RHSA-2009:1513; updating the affected packages is recommended.