Synopsis: Important: cups security update Issue date: 2008-02-25 CVE Names: CVE-2008-0596 CVE-2008-0597 CVE-2008-0882 SL 3 and SL 4 only A flaw was found in the way CUPS handled the addition and removal of remote shared printers via IPP. A remote attacker could send malicious UDP IPP packets causing the CUPS daemon to attempt to dereference already freed memory and crash. (CVE-2008-0597) A memory management flaw was found in the way CUPS handled the addition and removal of remote shared printers via IPP. When shared printer was removed, allocated memory was not properly freed, leading to a memory leak possibly causing CUPS daemon crash after exhausting available memory. (CVE-2008-0596) SL 5 only A flaw was found in the way CUPS handles the addition and removal of remote shared printers via IPP. A remote attacker could send malicious UDP IPP packets causing the CUPS daemon to crash. (CVE-2008-0882) SL 3.0.x SRPMS: cups-1.1.17-13.3.51.src.rpm i386: cups-1.1.17-13.3.51.i386.rpm cups-devel-1.1.17-13.3.51.i386.rpm cups-libs-1.1.17-13.3.51.i386.rpm x86_64: cups-1.1.17-13.3.51.x86_64.rpm cups-devel-1.1.17-13.3.51.x86_64.rpm cups-libs-1.1.17-13.3.51.i386.rpm cups-libs-1.1.17-13.3.51.x86_64.rpm SL 4.x SRPMS: cups-1.1.22-0.rc1.9.20.2.el4_6.5.src.rpm i386: cups-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm cups-devel-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm x86_64: cups-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpm cups-devel-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpm SL 5.x SRPMS: cups-1.2.4-11.14.el5_1.4.src.rpm i386: cups-1.2.4-11.14.el5_1.4.i386.rpm cups-devel-1.2.4-11.14.el5_1.4.i386.rpm cups-libs-1.2.4-11.14.el5_1.4.i386.rpm cups-lpd-1.2.4-11.14.el5_1.4.i386.rpm x86_64: cups-1.2.4-11.14.el5_1.4.x86_64.rpm cups-devel-1.2.4-11.14.el5_1.4.i386.rpm cups-devel-1.2.4-11.14.el5_1.4.x86_64.rpm cups-libs-1.2.4-11.14.el5_1.4.i386.rpm cups-libs-1.2.4-11.14.el5_1.4.x86_64.rpm cups-lpd-1.2.4-11.14.el5_1.4.x86_64.rpm -Connie Sieh -Troy Dawson