Skip to content

Security Advisory 重要(Important):cupsのセキュリティアップデート

アップデートID:

RHSA-2007:0720-3

タイプ:Security Advisory
重大性:重要/Important
発行日:2007年7月30日
最終更新日:2007年7月30日
影響のある製品: RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
OVAL: https://rhn.redhat.com/errata/RHSA-2007-0720.html
CVEs (cve.mitre.org): CVE-2007-3387

詳細

PDF処理のセキュリティ問題を修正したCUPSのアップデートパッケージがRed Hat Enterprise Linux 3、4、および5で利用可能になりました。

このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「重要(Important)」のセキュリティ問題と評価されています。

Common UNIX Printing System(CUPS)は、UNIX(R)オペレーティングシステム用のポータブルプリンティングレイヤを提供します。

Maurycy Prodeus氏が、CUPSでのPDFファイルの処理で整数オーバーフローの欠陥を発見しました。悪意のあるPDFファイルを作成することにより、印刷時に任意のコードが実行される可能性があります。(CVE-2007-3387)

CUPSのすべてのユーザは、この問題を解決するバックポートパッチを含む上記アップデートパッケージにアップグレードしてください。


解決法


このアップデートを適用する前に、ご使用のシステムに関係するリリース済みのエラータ/Errataがすべて適用されていることを確認してください。

このアップデートは、Red Hat Networkを通じて入手できます。


アップデートパッケージ

RHEL Desktop Workstation (v. 5 client)

IA-32:
cups-devel-1.2.4-11.5.3.el5.i386.rpm     30cb103baa067da1995217a57501382b
 
x86_64:
cups-devel-1.2.4-11.5.3.el5.i386.rpm     30cb103baa067da1995217a57501382b
cups-devel-1.2.4-11.5.3.el5.x86_64.rpm     47f1a8830e97a1cb652bac33978a02ef
 
Red Hat Desktop (v. 3)

SRPMS:
cups-1.1.17-13.3.45.src.rpm     72172a8c6f26afd39a4c80c2b539e2b3
 
IA-32:
cups-1.1.17-13.3.45.i386.rpm     8353393188789e8dcdccbf9e13c1e5fe
cups-devel-1.1.17-13.3.45.i386.rpm     a0c44eacd1b1808af15c1d20ee430728
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
 
x86_64:
cups-1.1.17-13.3.45.x86_64.rpm     c2acc3c7b8c4e0b0b69071cc9835e17a
cups-devel-1.1.17-13.3.45.x86_64.rpm     1cd5f8c505f26ff6ca1ea1b3a222ac0b
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.x86_64.rpm     07417f9c72d4943329e4c32829dc5fad
 
Red Hat Desktop (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.20.2.src.rpm     33524aeaefc2a0c0acb71dc7cdf1b91e
 
IA-32:
cups-1.1.22-0.rc1.9.20.2.i386.rpm     878a3872b94371416b9d096baea6d3f5
cups-devel-1.1.22-0.rc1.9.20.2.i386.rpm     ceff40cb7cc26c0b26d3281aa31af1fb
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
 
x86_64:
cups-1.1.22-0.rc1.9.20.2.x86_64.rpm     4de591b041cc0ab7abdd92cc268deb4a
cups-devel-1.1.22-0.rc1.9.20.2.x86_64.rpm     1f7527f008604f7bb8b496d626169819
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.x86_64.rpm     22f106e3aad6bffd2cbd49a0ce40f73a
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
cups-1.2.4-11.5.3.el5.src.rpm     0714cb20edba7ab50c53467e4b587635
 
IA-32:
cups-1.2.4-11.5.3.el5.i386.rpm     0cfe9a8ec8140d31bc1a7fb40f6a0034
cups-devel-1.2.4-11.5.3.el5.i386.rpm     30cb103baa067da1995217a57501382b
cups-libs-1.2.4-11.5.3.el5.i386.rpm     89a43749b68a82b95c92b5e344be31eb
cups-lpd-1.2.4-11.5.3.el5.i386.rpm     8a336e18ba4528de83dc6ea93e75bb45
 
IA-64:
cups-1.2.4-11.5.3.el5.ia64.rpm     bade98ac21654df52491801daeb5ae1d
cups-devel-1.2.4-11.5.3.el5.ia64.rpm     2a9a859fef7cf1224139b5792f7c1dfc
cups-libs-1.2.4-11.5.3.el5.i386.rpm     89a43749b68a82b95c92b5e344be31eb
cups-libs-1.2.4-11.5.3.el5.ia64.rpm     07dae4825d3c9097fc5e98121168b2d8
cups-lpd-1.2.4-11.5.3.el5.ia64.rpm     fb4551af42000d6974476abf24c64b84
 
PPC:
cups-1.2.4-11.5.3.el5.ppc.rpm     511dcb2871ca8253771781b755d278ed
cups-devel-1.2.4-11.5.3.el5.ppc.rpm     c530439d06e6267a7066410f9bdc7134
cups-devel-1.2.4-11.5.3.el5.ppc64.rpm     86e19d046a759e574dc7408cc7294cb5
cups-libs-1.2.4-11.5.3.el5.ppc.rpm     e75a8edb42924b43bb0c67d429e9a6c1
cups-libs-1.2.4-11.5.3.el5.ppc64.rpm     521c022a74f54a5908187009ed0bbf8c
cups-lpd-1.2.4-11.5.3.el5.ppc.rpm     087f3848b4dbe1e6343e7e16d2847ed7
 
s390x:
cups-1.2.4-11.5.3.el5.s390x.rpm     5c7217758f2ffb51a3a19d6a5f772999
cups-devel-1.2.4-11.5.3.el5.s390.rpm     a0cb956d378cd528ce516d744bdac49f
cups-devel-1.2.4-11.5.3.el5.s390x.rpm     2602ce590ab052c3f9c577a5170c4467
cups-libs-1.2.4-11.5.3.el5.s390.rpm     ad545473a39aeb0833f5573fb4035051
cups-libs-1.2.4-11.5.3.el5.s390x.rpm     cee0ff2811bd78f6fb512d6f5a312f99
cups-lpd-1.2.4-11.5.3.el5.s390x.rpm     bf635d1926cb2099f21d74af8768d69d
 
x86_64:
cups-1.2.4-11.5.3.el5.x86_64.rpm     cfde836d51cd215fdb19165b64916d25
cups-devel-1.2.4-11.5.3.el5.i386.rpm     30cb103baa067da1995217a57501382b
cups-devel-1.2.4-11.5.3.el5.x86_64.rpm     47f1a8830e97a1cb652bac33978a02ef
cups-libs-1.2.4-11.5.3.el5.i386.rpm     89a43749b68a82b95c92b5e344be31eb
cups-libs-1.2.4-11.5.3.el5.x86_64.rpm     56a68177647348776df843ae1c50640c
cups-lpd-1.2.4-11.5.3.el5.x86_64.rpm     d1e59788b3d127fc38a2bc601960e208
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
cups-1.1.17-13.3.45.src.rpm     72172a8c6f26afd39a4c80c2b539e2b3
 
IA-32:
cups-1.1.17-13.3.45.i386.rpm     8353393188789e8dcdccbf9e13c1e5fe
cups-devel-1.1.17-13.3.45.i386.rpm     a0c44eacd1b1808af15c1d20ee430728
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
 
IA-64:
cups-1.1.17-13.3.45.ia64.rpm     490581994f6a67fe6331b2be44dd1995
cups-devel-1.1.17-13.3.45.ia64.rpm     c4c6c52a0d7b40e9b61b6d465d287fa5
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.ia64.rpm     abb3146696bbb0f87cc44f40a94d1eb3
 
PPC:
cups-1.1.17-13.3.45.ppc.rpm     858c3391c6522d07c9fb66a6070ca601
cups-devel-1.1.17-13.3.45.ppc.rpm     1b3482384aa62b3b3e15b18acfcf4c88
cups-libs-1.1.17-13.3.45.ppc.rpm     c3f1f7fa1fa48aca2cf21232504b7e72
cups-libs-1.1.17-13.3.45.ppc64.rpm     03f0e684b27d7d25a96df16d55ce524c
 
s390:
cups-1.1.17-13.3.45.s390.rpm     aee3e6be1c42e83b0172b60ba16b898a
cups-devel-1.1.17-13.3.45.s390.rpm     bd1328bda7171c4c925943c2697d6be8
cups-libs-1.1.17-13.3.45.s390.rpm     74dcd7b6b89caf9442eb934bec67ffea
 
s390x:
cups-1.1.17-13.3.45.s390x.rpm     11871e6eebfc7c0cd24266b64eb0d38c
cups-devel-1.1.17-13.3.45.s390x.rpm     f3bfdf692b1b37b39671edeb0ca6a3de
cups-libs-1.1.17-13.3.45.s390.rpm     74dcd7b6b89caf9442eb934bec67ffea
cups-libs-1.1.17-13.3.45.s390x.rpm     d9d1c1429fe8d4c377fe93d6a2b60d6c
 
x86_64:
cups-1.1.17-13.3.45.x86_64.rpm     c2acc3c7b8c4e0b0b69071cc9835e17a
cups-devel-1.1.17-13.3.45.x86_64.rpm     1cd5f8c505f26ff6ca1ea1b3a222ac0b
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.x86_64.rpm     07417f9c72d4943329e4c32829dc5fad
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.20.2.src.rpm     33524aeaefc2a0c0acb71dc7cdf1b91e
 
IA-32:
cups-1.1.22-0.rc1.9.20.2.i386.rpm     878a3872b94371416b9d096baea6d3f5
cups-devel-1.1.22-0.rc1.9.20.2.i386.rpm     ceff40cb7cc26c0b26d3281aa31af1fb
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
 
IA-64:
cups-1.1.22-0.rc1.9.20.2.ia64.rpm     cce185d43e3dd501422a3d33d5a1a4f2
cups-devel-1.1.22-0.rc1.9.20.2.ia64.rpm     73f18742e7b21c45e0a839d0f7b8938a
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.ia64.rpm     7f38c2d05cf1f1a9ac19c3262d9ecf61
 
PPC:
cups-1.1.22-0.rc1.9.20.2.ppc.rpm     5eec914b1712aeef4686b197e5dfd28f
cups-devel-1.1.22-0.rc1.9.20.2.ppc.rpm     6e559f57f7ed703b760c8a549af198fa
cups-libs-1.1.22-0.rc1.9.20.2.ppc.rpm     26a048eea7b36232f74cdbcb16cf2a7e
cups-libs-1.1.22-0.rc1.9.20.2.ppc64.rpm     a316070dc7d0962ac2c7a6a3a6a9c5bb
 
s390:
cups-1.1.22-0.rc1.9.20.2.s390.rpm     f8034119545b60e405d834be3c1aef7d
cups-devel-1.1.22-0.rc1.9.20.2.s390.rpm     e9b0c5e87623ab5569ba9b4bbdaa4c98
cups-libs-1.1.22-0.rc1.9.20.2.s390.rpm     f4547002d8ded0872a42136be1d31874
 
s390x:
cups-1.1.22-0.rc1.9.20.2.s390x.rpm     c9cb24a221d8646970fe03439776acd6
cups-devel-1.1.22-0.rc1.9.20.2.s390x.rpm     6213a014e214d0b13204a210f725f6e8
cups-libs-1.1.22-0.rc1.9.20.2.s390.rpm     f4547002d8ded0872a42136be1d31874
cups-libs-1.1.22-0.rc1.9.20.2.s390x.rpm     75a87c119d32a6b9cb6a6c3e56f75121
 
x86_64:
cups-1.1.22-0.rc1.9.20.2.x86_64.rpm     4de591b041cc0ab7abdd92cc268deb4a
cups-devel-1.1.22-0.rc1.9.20.2.x86_64.rpm     1f7527f008604f7bb8b496d626169819
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.x86_64.rpm     22f106e3aad6bffd2cbd49a0ce40f73a
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
cups-1.2.4-11.5.3.el5.src.rpm     0714cb20edba7ab50c53467e4b587635
 
IA-32:
cups-1.2.4-11.5.3.el5.i386.rpm     0cfe9a8ec8140d31bc1a7fb40f6a0034
cups-libs-1.2.4-11.5.3.el5.i386.rpm     89a43749b68a82b95c92b5e344be31eb
cups-lpd-1.2.4-11.5.3.el5.i386.rpm     8a336e18ba4528de83dc6ea93e75bb45
 
x86_64:
cups-1.2.4-11.5.3.el5.x86_64.rpm     cfde836d51cd215fdb19165b64916d25
cups-libs-1.2.4-11.5.3.el5.i386.rpm     89a43749b68a82b95c92b5e344be31eb
cups-libs-1.2.4-11.5.3.el5.x86_64.rpm     56a68177647348776df843ae1c50640c
cups-lpd-1.2.4-11.5.3.el5.x86_64.rpm     d1e59788b3d127fc38a2bc601960e208
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
cups-1.1.17-13.3.45.src.rpm     72172a8c6f26afd39a4c80c2b539e2b3
 
IA-32:
cups-1.1.17-13.3.45.i386.rpm     8353393188789e8dcdccbf9e13c1e5fe
cups-devel-1.1.17-13.3.45.i386.rpm     a0c44eacd1b1808af15c1d20ee430728
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
 
IA-64:
cups-1.1.17-13.3.45.ia64.rpm     490581994f6a67fe6331b2be44dd1995
cups-devel-1.1.17-13.3.45.ia64.rpm     c4c6c52a0d7b40e9b61b6d465d287fa5
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.ia64.rpm     abb3146696bbb0f87cc44f40a94d1eb3
 
x86_64:
cups-1.1.17-13.3.45.x86_64.rpm     c2acc3c7b8c4e0b0b69071cc9835e17a
cups-devel-1.1.17-13.3.45.x86_64.rpm     1cd5f8c505f26ff6ca1ea1b3a222ac0b
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.x86_64.rpm     07417f9c72d4943329e4c32829dc5fad
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.20.2.src.rpm     33524aeaefc2a0c0acb71dc7cdf1b91e
 
IA-32:
cups-1.1.22-0.rc1.9.20.2.i386.rpm     878a3872b94371416b9d096baea6d3f5
cups-devel-1.1.22-0.rc1.9.20.2.i386.rpm     ceff40cb7cc26c0b26d3281aa31af1fb
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
 
IA-64:
cups-1.1.22-0.rc1.9.20.2.ia64.rpm     cce185d43e3dd501422a3d33d5a1a4f2
cups-devel-1.1.22-0.rc1.9.20.2.ia64.rpm     73f18742e7b21c45e0a839d0f7b8938a
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.ia64.rpm     7f38c2d05cf1f1a9ac19c3262d9ecf61
 
x86_64:
cups-1.1.22-0.rc1.9.20.2.x86_64.rpm     4de591b041cc0ab7abdd92cc268deb4a
cups-devel-1.1.22-0.rc1.9.20.2.x86_64.rpm     1f7527f008604f7bb8b496d626169819
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.x86_64.rpm     22f106e3aad6bffd2cbd49a0ce40f73a
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
cups-1.1.17-13.3.45.src.rpm     72172a8c6f26afd39a4c80c2b539e2b3
 
IA-32:
cups-1.1.17-13.3.45.i386.rpm     8353393188789e8dcdccbf9e13c1e5fe
cups-devel-1.1.17-13.3.45.i386.rpm     a0c44eacd1b1808af15c1d20ee430728
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
 
IA-64:
cups-1.1.17-13.3.45.ia64.rpm     490581994f6a67fe6331b2be44dd1995
cups-devel-1.1.17-13.3.45.ia64.rpm     c4c6c52a0d7b40e9b61b6d465d287fa5
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.ia64.rpm     abb3146696bbb0f87cc44f40a94d1eb3
 
x86_64:
cups-1.1.17-13.3.45.x86_64.rpm     c2acc3c7b8c4e0b0b69071cc9835e17a
cups-devel-1.1.17-13.3.45.x86_64.rpm     1cd5f8c505f26ff6ca1ea1b3a222ac0b
cups-libs-1.1.17-13.3.45.i386.rpm     21b9e252d496a5fb043bd9a52a46572a
cups-libs-1.1.17-13.3.45.x86_64.rpm     07417f9c72d4943329e4c32829dc5fad
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
cups-1.1.22-0.rc1.9.20.2.src.rpm     33524aeaefc2a0c0acb71dc7cdf1b91e
 
IA-32:
cups-1.1.22-0.rc1.9.20.2.i386.rpm     878a3872b94371416b9d096baea6d3f5
cups-devel-1.1.22-0.rc1.9.20.2.i386.rpm     ceff40cb7cc26c0b26d3281aa31af1fb
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
 
IA-64:
cups-1.1.22-0.rc1.9.20.2.ia64.rpm     cce185d43e3dd501422a3d33d5a1a4f2
cups-devel-1.1.22-0.rc1.9.20.2.ia64.rpm     73f18742e7b21c45e0a839d0f7b8938a
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.ia64.rpm     7f38c2d05cf1f1a9ac19c3262d9ecf61
 
x86_64:
cups-1.1.22-0.rc1.9.20.2.x86_64.rpm     4de591b041cc0ab7abdd92cc268deb4a
cups-devel-1.1.22-0.rc1.9.20.2.x86_64.rpm     1f7527f008604f7bb8b496d626169819
cups-libs-1.1.22-0.rc1.9.20.2.i386.rpm     a0f599bcdb6fa8bfb9913da79c83351f
cups-libs-1.1.22-0.rc1.9.20.2.x86_64.rpm     22f106e3aad6bffd2cbd49a0ce40f73a
 
(The unlinked packages above are only available from the Red Hat Network)


バグフィックス (詳細は、bugzilla/バグジラ[英語]を御覧ください。)

248194 - CVE-2007-3387 xpdf integer overflow


参照





ここに在るパッケージはセキュリティの為、Red Hat, Inc. によって、GPG認証されています。
認証キー及び詳細は以下を御覧下さい。
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/