Multiple vulnerabilities were discovered in the Common Unix Printing System (CUPS). Several of these issues represent the potential for a remote compromise or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:
/etc/cups/certs/
allow local users with lp privileges to create or overwrite
arbitrary files. This is not present in the potato version.Even though we tried very hard to fix all problems in the packages for potato as well, the packages may still contain other security related problems. Hence, we advise users of potato systems using CUPS to upgrade to woody soon.
For the current stable distribution (woody), these problems have been fixed in version 1.1.14-4.3.
For the old stable distribution (potato), these problems have been fixed in version 1.0.4-12.1.
For the unstable distribution (sid), these problems have been fixed in version 1.1.18-1.
We recommend that you upgrade your CUPS packages immediately.
MD5 checksums of the listed files are available in the original advisory.
MD5 checksums of the listed files are available in the revised advisory.