Skip to content

Security Advisory 中(Moderate):cupsのセキュリティアップデート

アップデートID:

RHSA-2007:0123-8

タイプ:Security Advisory
重大性:中/Moderate
発行日:2007年4月16日
最終更新日:2007年4月16日
影響のある製品: RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
OVAL: https://rhn.redhat.com/errata/RHSA-2007-0123.html
CVEs (cve.mitre.org): CVE-2007-0720

詳細

セキュリティ問題を修正したCUPSのアップデートパッケージがRed Hat Enterprise Linux 3、4、および5で利用可能になりました。

このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「中(Moderate)」のセキュリティ問題と評価されています。

Common UNIX Printing System(CUPS)は、UNIX(R)オペレーティングシステム用のポータブルプリンティングレイヤを提供します。

CUPSのSSLネゴシエーションの処理でバグが見つかりました。CUPSデーモンにアクセスできるリモートユーザが他のCUPSユーザに対してサービ ス拒否を引き起こすことができます。(CVE-2007-0720)

CUPSのすべてのユーザは、タイムアウトを導入するバックポートパッチを含む上記アップデートパッケージにアップグレードしてください。このタイムア ウトによって、接続を任意の長時間オープンしておくことはできなくなります。


解決法

このアップデートを適用する前に、ご使用のシステムに関係するリリース済みのエラータ/Errataがすべて適用されていることを確認してください。

このアップデートは、Red Hat Networkを通じて入手できます。


アップデートパッケージ

RHEL Desktop Workstation (v. 5 client)

IA-32:
cups-devel-1.2.4-11.5.1.el5.i386.rpm     7c2b36a160173d8b9a1f8845558d2e7d
 
x86_64:
cups-devel-1.2.4-11.5.1.el5.i386.rpm     7c2b36a160173d8b9a1f8845558d2e7d
cups-devel-1.2.4-11.5.1.el5.x86_64.rpm     c97a522241c8e9a965059f8d55ec3fcf
 
Red Hat Desktop (v. 3)

SRPMS:
cups-1.1.17-13.3.42.src.rpm     1066e31f6fcccc64457138cf8fbde67c
 
IA-32:
cups-1.1.17-13.3.42.i386.rpm     3b829f6f4c8b85cb335755fd915e67f9
cups-devel-1.1.17-13.3.42.i386.rpm     b719ac88e6ccad1fbf35d5ae5ce6d147
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
 
x86_64:
cups-1.1.17-13.3.42.x86_64.rpm     90dc20ae6f3f172a58113129585e3a45
cups-devel-1.1.17-13.3.42.x86_64.rpm     572319d374183c2186c3e117e9d8d83a
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.x86_64.rpm     a2be68b47e8c77c38a4c18232e8c7e2e
 
Red Hat Desktop (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.18.src.rpm     3a23c9f89297d3bb37b557fc262ad4f3
 
IA-32:
cups-1.1.22-0.rc1.9.18.i386.rpm     87265fe535e63a74c4a1030c2c19500e
cups-devel-1.1.22-0.rc1.9.18.i386.rpm     94da2a1123245fe1914da2170804c5a9
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
 
x86_64:
cups-1.1.22-0.rc1.9.18.x86_64.rpm     30a1fe74e789eabefab0bed4a7b04349
cups-devel-1.1.22-0.rc1.9.18.x86_64.rpm     38905d4725b47e04372551842d4d0235
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.x86_64.rpm     98ca79902f7f5d61679e1a2ea20dd5b4
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
cups-1.2.4-11.5.1.el5.src.rpm     57f8fc7374a548ad38d598fc13ca5e3b
 
IA-32:
cups-1.2.4-11.5.1.el5.i386.rpm     a17c70e4fe72b49af90d261d8c5710d9
cups-devel-1.2.4-11.5.1.el5.i386.rpm     7c2b36a160173d8b9a1f8845558d2e7d
cups-libs-1.2.4-11.5.1.el5.i386.rpm     519dd6586f4bd3a11aee34bec74f2a00
cups-lpd-1.2.4-11.5.1.el5.i386.rpm     a82e39a2fb8bb391622d97467ff4944d
 
IA-64:
cups-1.2.4-11.5.1.el5.ia64.rpm     8e50b0839657a6d734ffbef2100fefe4
cups-devel-1.2.4-11.5.1.el5.ia64.rpm     f53034ada9e877a4436d6b7fc89765f7
cups-libs-1.2.4-11.5.1.el5.i386.rpm     519dd6586f4bd3a11aee34bec74f2a00
cups-libs-1.2.4-11.5.1.el5.ia64.rpm     e10be7e4c9ee47cf581e60712fac1952
cups-lpd-1.2.4-11.5.1.el5.ia64.rpm     6b9953d00f4323acfe3b0efbdf095919
 
PPC:
cups-1.2.4-11.5.1.el5.ppc.rpm     f2b94bfb2b86ddcc398486f1620c5319
cups-devel-1.2.4-11.5.1.el5.ppc.rpm     cff799b766072081ecdd784584d3220b
cups-devel-1.2.4-11.5.1.el5.ppc64.rpm     89f0724c0a9ecad7a2e2a8511d913295
cups-libs-1.2.4-11.5.1.el5.ppc.rpm     befef14bf774d62934da4d342dea01b6
cups-libs-1.2.4-11.5.1.el5.ppc64.rpm     00a9ff82fa7da96ebba66794c052edf5
cups-lpd-1.2.4-11.5.1.el5.ppc.rpm     7d7b2440e8d4589677f31071b348febd
 
s390x:
cups-1.2.4-11.5.1.el5.s390x.rpm     6cc834e166a2a287eec4e78d56a4d93a
cups-devel-1.2.4-11.5.1.el5.s390.rpm     50dc65113a2f3eea2cf30e5e9ef33a81
cups-devel-1.2.4-11.5.1.el5.s390x.rpm     89194aa4511c8379ec0009e3055b4032
cups-libs-1.2.4-11.5.1.el5.s390.rpm     82873ebb32bc1c241ce4f8a66225ebaa
cups-libs-1.2.4-11.5.1.el5.s390x.rpm     95688526be7c36058c4b4b9d8cc7385c
cups-lpd-1.2.4-11.5.1.el5.s390x.rpm     a775792ff310abaf91faf80e885b64c8
 
x86_64:
cups-1.2.4-11.5.1.el5.x86_64.rpm     9cfd2391c42178312a1cf28ed1d3d67c
cups-devel-1.2.4-11.5.1.el5.i386.rpm     7c2b36a160173d8b9a1f8845558d2e7d
cups-devel-1.2.4-11.5.1.el5.x86_64.rpm     c97a522241c8e9a965059f8d55ec3fcf
cups-libs-1.2.4-11.5.1.el5.i386.rpm     519dd6586f4bd3a11aee34bec74f2a00
cups-libs-1.2.4-11.5.1.el5.x86_64.rpm     4f185a74627babbcac7e7a6a5d59735e
cups-lpd-1.2.4-11.5.1.el5.x86_64.rpm     e64d4f5087ad254ad5673ba05419c958
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
cups-1.1.17-13.3.42.src.rpm     1066e31f6fcccc64457138cf8fbde67c
 
IA-32:
cups-1.1.17-13.3.42.i386.rpm     3b829f6f4c8b85cb335755fd915e67f9
cups-devel-1.1.17-13.3.42.i386.rpm     b719ac88e6ccad1fbf35d5ae5ce6d147
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
 
IA-64:
cups-1.1.17-13.3.42.ia64.rpm     0353e87f40559c2757d645399c39ce4e
cups-devel-1.1.17-13.3.42.ia64.rpm     bfb1c7db0e9ecf29ea19cfc1c1b1b0db
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.ia64.rpm     51d9d43507125a1cf8b5a9f492dc4c5c
 
PPC:
cups-1.1.17-13.3.42.ppc.rpm     26a1f65d933edbba963234be65d7a496
cups-devel-1.1.17-13.3.42.ppc.rpm     2d9803700aff908a7435b9421fce1be2
cups-libs-1.1.17-13.3.42.ppc.rpm     8353d28f908dab4192ef1b306e9487ea
cups-libs-1.1.17-13.3.42.ppc64.rpm     20ff2a543d39c6f99921b807571f5624
 
s390:
cups-1.1.17-13.3.42.s390.rpm     73c17702d5d7202cb4fe05dd863eb5a8
cups-devel-1.1.17-13.3.42.s390.rpm     613fab2d2886afd7de71325034d002b7
cups-libs-1.1.17-13.3.42.s390.rpm     28f2fbd498caf0d377bd8421867083a7
 
s390x:
cups-1.1.17-13.3.42.s390x.rpm     348ba89bb9b86cbe39a1c12c34b4de43
cups-devel-1.1.17-13.3.42.s390x.rpm     ae83dac562cc57af1d291c89276c65f7
cups-libs-1.1.17-13.3.42.s390.rpm     28f2fbd498caf0d377bd8421867083a7
cups-libs-1.1.17-13.3.42.s390x.rpm     0545b833b59609ff3ed9d8bc09880f87
 
x86_64:
cups-1.1.17-13.3.42.x86_64.rpm     90dc20ae6f3f172a58113129585e3a45
cups-devel-1.1.17-13.3.42.x86_64.rpm     572319d374183c2186c3e117e9d8d83a
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.x86_64.rpm     a2be68b47e8c77c38a4c18232e8c7e2e
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.18.src.rpm     3a23c9f89297d3bb37b557fc262ad4f3
 
IA-32:
cups-1.1.22-0.rc1.9.18.i386.rpm     87265fe535e63a74c4a1030c2c19500e
cups-devel-1.1.22-0.rc1.9.18.i386.rpm     94da2a1123245fe1914da2170804c5a9
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
 
IA-64:
cups-1.1.22-0.rc1.9.18.ia64.rpm     a3e492bf1130ec273e160dfd7f2987f8
cups-devel-1.1.22-0.rc1.9.18.ia64.rpm     1d44406cfbc7b782d8f6215a17ee7890
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.ia64.rpm     56c1c5d17e3b7c723f39095f25e4a0a6
 
PPC:
cups-1.1.22-0.rc1.9.18.ppc.rpm     7fac9bb6c9b7b53019fd65c702063ae8
cups-devel-1.1.22-0.rc1.9.18.ppc.rpm     8f77aa28d24062a4bfaa5132a0953e7e
cups-libs-1.1.22-0.rc1.9.18.ppc.rpm     8eb06ae5021e1578c170edb6aeceada9
cups-libs-1.1.22-0.rc1.9.18.ppc64.rpm     5b80e95026f322732303383ebb42cabd
 
s390:
cups-1.1.22-0.rc1.9.18.s390.rpm     9fe916be58f3f377ce8b0ae5e55169b2
cups-devel-1.1.22-0.rc1.9.18.s390.rpm     da17b23d4d22cd561c66f3f68f5139ba
cups-libs-1.1.22-0.rc1.9.18.s390.rpm     2fe99c0ab0e1d1a230256000476f2487
 
s390x:
cups-1.1.22-0.rc1.9.18.s390x.rpm     d0e609f3c6ed845785f8da303b66fceb
cups-devel-1.1.22-0.rc1.9.18.s390x.rpm     1a329c78ae5dc22f2111c2fb4af0ed81
cups-libs-1.1.22-0.rc1.9.18.s390.rpm     2fe99c0ab0e1d1a230256000476f2487
cups-libs-1.1.22-0.rc1.9.18.s390x.rpm     4d9638c989c733e13224e6d9ea9d7c5e
 
x86_64:
cups-1.1.22-0.rc1.9.18.x86_64.rpm     30a1fe74e789eabefab0bed4a7b04349
cups-devel-1.1.22-0.rc1.9.18.x86_64.rpm     38905d4725b47e04372551842d4d0235
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.x86_64.rpm     98ca79902f7f5d61679e1a2ea20dd5b4
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
cups-1.2.4-11.5.1.el5.src.rpm     57f8fc7374a548ad38d598fc13ca5e3b
 
IA-32:
cups-1.2.4-11.5.1.el5.i386.rpm     a17c70e4fe72b49af90d261d8c5710d9
cups-libs-1.2.4-11.5.1.el5.i386.rpm     519dd6586f4bd3a11aee34bec74f2a00
cups-lpd-1.2.4-11.5.1.el5.i386.rpm     a82e39a2fb8bb391622d97467ff4944d
 
x86_64:
cups-1.2.4-11.5.1.el5.x86_64.rpm     9cfd2391c42178312a1cf28ed1d3d67c
cups-libs-1.2.4-11.5.1.el5.i386.rpm     519dd6586f4bd3a11aee34bec74f2a00
cups-libs-1.2.4-11.5.1.el5.x86_64.rpm     4f185a74627babbcac7e7a6a5d59735e
cups-lpd-1.2.4-11.5.1.el5.x86_64.rpm     e64d4f5087ad254ad5673ba05419c958
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
cups-1.1.17-13.3.42.src.rpm     1066e31f6fcccc64457138cf8fbde67c
 
IA-32:
cups-1.1.17-13.3.42.i386.rpm     3b829f6f4c8b85cb335755fd915e67f9
cups-devel-1.1.17-13.3.42.i386.rpm     b719ac88e6ccad1fbf35d5ae5ce6d147
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
 
IA-64:
cups-1.1.17-13.3.42.ia64.rpm     0353e87f40559c2757d645399c39ce4e
cups-devel-1.1.17-13.3.42.ia64.rpm     bfb1c7db0e9ecf29ea19cfc1c1b1b0db
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.ia64.rpm     51d9d43507125a1cf8b5a9f492dc4c5c
 
x86_64:
cups-1.1.17-13.3.42.x86_64.rpm     90dc20ae6f3f172a58113129585e3a45
cups-devel-1.1.17-13.3.42.x86_64.rpm     572319d374183c2186c3e117e9d8d83a
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.x86_64.rpm     a2be68b47e8c77c38a4c18232e8c7e2e
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.18.src.rpm     3a23c9f89297d3bb37b557fc262ad4f3
 
IA-32:
cups-1.1.22-0.rc1.9.18.i386.rpm     87265fe535e63a74c4a1030c2c19500e
cups-devel-1.1.22-0.rc1.9.18.i386.rpm     94da2a1123245fe1914da2170804c5a9
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
 
IA-64:
cups-1.1.22-0.rc1.9.18.ia64.rpm     a3e492bf1130ec273e160dfd7f2987f8
cups-devel-1.1.22-0.rc1.9.18.ia64.rpm     1d44406cfbc7b782d8f6215a17ee7890
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.ia64.rpm     56c1c5d17e3b7c723f39095f25e4a0a6
 
x86_64:
cups-1.1.22-0.rc1.9.18.x86_64.rpm     30a1fe74e789eabefab0bed4a7b04349
cups-devel-1.1.22-0.rc1.9.18.x86_64.rpm     38905d4725b47e04372551842d4d0235
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.x86_64.rpm     98ca79902f7f5d61679e1a2ea20dd5b4
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
cups-1.1.17-13.3.42.src.rpm     1066e31f6fcccc64457138cf8fbde67c
 
IA-32:
cups-1.1.17-13.3.42.i386.rpm     3b829f6f4c8b85cb335755fd915e67f9
cups-devel-1.1.17-13.3.42.i386.rpm     b719ac88e6ccad1fbf35d5ae5ce6d147
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
 
IA-64:
cups-1.1.17-13.3.42.ia64.rpm     0353e87f40559c2757d645399c39ce4e
cups-devel-1.1.17-13.3.42.ia64.rpm     bfb1c7db0e9ecf29ea19cfc1c1b1b0db
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.ia64.rpm     51d9d43507125a1cf8b5a9f492dc4c5c
 
x86_64:
cups-1.1.17-13.3.42.x86_64.rpm     90dc20ae6f3f172a58113129585e3a45
cups-devel-1.1.17-13.3.42.x86_64.rpm     572319d374183c2186c3e117e9d8d83a
cups-libs-1.1.17-13.3.42.i386.rpm     af104cbb51444df2c82735c0f0516efa
cups-libs-1.1.17-13.3.42.x86_64.rpm     a2be68b47e8c77c38a4c18232e8c7e2e
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.18.src.rpm     3a23c9f89297d3bb37b557fc262ad4f3
 
IA-32:
cups-1.1.22-0.rc1.9.18.i386.rpm     87265fe535e63a74c4a1030c2c19500e
cups-devel-1.1.22-0.rc1.9.18.i386.rpm     94da2a1123245fe1914da2170804c5a9
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
 
IA-64:
cups-1.1.22-0.rc1.9.18.ia64.rpm     a3e492bf1130ec273e160dfd7f2987f8
cups-devel-1.1.22-0.rc1.9.18.ia64.rpm     1d44406cfbc7b782d8f6215a17ee7890
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.ia64.rpm     56c1c5d17e3b7c723f39095f25e4a0a6
 
x86_64:
cups-1.1.22-0.rc1.9.18.x86_64.rpm     30a1fe74e789eabefab0bed4a7b04349
cups-devel-1.1.22-0.rc1.9.18.x86_64.rpm     38905d4725b47e04372551842d4d0235
cups-libs-1.1.22-0.rc1.9.18.i386.rpm     bf284b5fa688b1a892f7d5bae0b10aa2
cups-libs-1.1.22-0.rc1.9.18.x86_64.rpm     98ca79902f7f5d61679e1a2ea20dd5b4
 
(The unlinked packages above are only available from the Red Hat Network)


バグフィックス (詳細は、bugzilla/バグジラ[英語]を御覧ください。)

232241 - CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server


参照


キーワード

cups, dos, negotiation, ssl


ここに在るパッケージはセキュリティの為、Red Hat, Inc. によって、GPG認証されています。
認証キー及び詳細は以下を御覧下さい。
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/