Discussion:
Bug#947832: buster-pu: package cups/2.2.10-6+deb10u2
(too old to reply)
Didier 'OdyX' Raboud
2019-12-31 13:30:01 UTC
Permalink
Package: release.debian.org
Severity: normal
Tags: buster
User: ***@packages.debian.org
Usertags: pu

Dear Stable Release Team,

CVE-2019-2228 affects stable's cups (see #946782); and I'd also like to fix
another memory leak (#946941).

My proposed changelog would be:

cups (2.2.10-6+deb10u2) buster; urgency=medium

* Backport upstream security fixes:
- Fix memory leak in ppdOpen (Closes: #946941)
- CVE-2019-2228: The `ippSetValuetag` function did not validate the
default language value (Closes: #946782)

-- Didier Raboud <***@debian.org> Tue, 31 Dec 2019 14:16:46 +0100



 the proposed debdiff is attached.

Cheers,
OdyX
Adam D. Barratt
2020-01-18 20:50:07 UTC
Permalink
Control: tags -1 + confirmed
Post by Didier 'OdyX' Raboud
CVE-2019-2228 affects stable's cups (see #946782); and I'd also like
to fix another memory leak (#946941).
cups (2.2.10-6+deb10u2) buster; urgency=medium
The attached debdiff, otoh, had

+cups (2.2.10-6+deb10u2) buster-security; urgency=high

Please feel free to go ahead, with the non-security version. :-)

Regards,

Adam
Didier 'OdyX' Raboud
2020-01-19 09:10:01 UTC
Permalink
Post by Adam D. Barratt
Control: tags -1 + confirmed
Post by Didier 'OdyX' Raboud
CVE-2019-2228 affects stable's cups (see #946782); and I'd also like
to fix another memory leak (#946941).
cups (2.2.10-6+deb10u2) buster; urgency=medium
The attached debdiff, otoh, had
+cups (2.2.10-6+deb10u2) buster-security; urgency=high
Please feel free to go ahead, with the non-security version. :-)
Uploaded, thanks for the authorization!

Cheers,
OdyX
Adam D Barratt
2020-01-20 23:10:02 UTC
Permalink
package release.debian.org
tags 947832 = buster pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian buster.

Thanks for your contribution!

Upload details
==============

Package: cups
Version: 2.2.10-6+deb10u2

Explanation: fix memory leak in ppdOpen; fix validation of default language in ippSetValuetag [CVE-2019-2228]
Loading...