USN-6844-1 fixed vulnerabilities in the CUPS package. The update
lead to the discovery of a regression in CUPS with regards to
how the cupsd daemon handles Listen configuration directive.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Rory McNamara discovered that when starting the cupsd server with a
Listen configuration item, the cupsd process fails to validate if
bind call passed. An attacker could possibly trick cupsd to perform
an arbitrary chmod of the provided argument, providing world-writable
access to the target.
More Stories
pgadmin4-9.2-1.fc41
FEDORA-2025-49d6f62c0e Packages in this update: pgadmin4-9.2-1.fc41 Update description: Update to pgadmin-9.2. Read More
java-latest-openjdk-24.0.1.0.9-1.rolling.el9
FEDORA-EPEL-2025-69dbee5b72 Packages in this update: java-latest-openjdk-24.0.1.0.9-1.rolling.el9 Update description: April 2025 CPU Fixed alternatives priority Java-latest-openjdk updated to jdk 24 Read...
java-latest-openjdk-24.0.1.0.9-1.rolling.el10_0 java-latest-openjdk-portable-24.0.1.0.9-1.rolling.el8
FEDORA-EPEL-2025-eb6bb14364 Packages in this update: java-latest-openjdk-24.0.1.0.9-1.rolling.el10_0 java-latest-openjdk-portable-24.0.1.0.9-1.rolling.el8 Update description: April 2025 CPU First jdk24 for epel10 Read More
java-1.8.0-openjdk-portable-1.8.0.452.b06-2.fc39 java-17-openjdk-portable-17.0.15.0.6-1.fc40
FEDORA-2025-5c15947cd4 Packages in this update: java-17-openjdk-portable-17.0.15.0.6-1.fc40 java-1.8.0-openjdk-portable-1.8.0.452.b06-2.fc39 Update description: April 2025 CPU Read More
java-1.8.0-openjdk-1.8.0.452.b06-1.fc40
FEDORA-2025-b6323169bc Packages in this update: java-1.8.0-openjdk-1.8.0.452.b06-1.fc40 Update description: April 2025 CPU Read More
java-1.8.0-openjdk-1.8.0.452.b06-1.fc41
FEDORA-2025-e81dbae527 Packages in this update: java-1.8.0-openjdk-1.8.0.452.b06-1.fc41 Update description: April 2025 CPU Read More