[CLSA-2025:1759329269] cups: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-10-01 14:34:46 UTC
Description:
- CVE-2023-4504: validate length of attacker-crafted PPD PostScript documents to prevent heap-based buffer overflow and possible code execution - CVE-2025-58060: fix authentication bypass issue caused by not checking password when AuthType is not Basic.
Updated packages:
  • cups-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:87fce60bcb4a1f94626d0701924b99e3f6c16ac2de8af16a4adf0e84634c24a7
  • cups-client-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:c107744508ccb2e7fe718529ca854ada8e1f5c4490bb82635a0b0e006ec93544
  • cups-devel-2.2.6-40.el8.tuxcare.els5.i686.rpm
    sha:3f3e669e26fc32da1fd8f8c7cd4988ea98528a2d69e15d1dff5da53ef3c1e333
  • cups-devel-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:d37ef52e8cd6c68a140fe11927eb943e78c47460503ac7612f304d3c6d5ed541
  • cups-filesystem-2.2.6-40.el8.tuxcare.els5.noarch.rpm
    sha:7f0523ebd38053cfaf43ed69dfe9314f6b57f21188bc78509517389bde613cfd
  • cups-ipptool-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:6654d57de52d00063f7a8a048314226fcdb315cffe802916550b35bdc75196c0
  • cups-libs-2.2.6-40.el8.tuxcare.els5.i686.rpm
    sha:090a447a2bc49d3468f8a8524feec8660728f6fa3770c2735bce89cfa19a983a
  • cups-libs-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:261f7b289324022fdc4fd4e191843e5463e206a35421659eae4932ccbe3e101d
  • cups-lpd-2.2.6-40.el8.tuxcare.els5.x86_64.rpm
    sha:9915e0a9175cbf6c1664f68599c354b8ad31f57027f5c7f3ba676737ca1b7cf9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.