-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 -------------------------------------------------------------------------- Turbolinux Security Advisory TLSA-2008-43 http://www.turbolinux.co.jp/security/ security-team@turbolinux.co.jp -------------------------------------------------------------------------- Original released date: 04 Dec 2008 Last revised: 04 Dec 2008 Package: cups Summary: Multiple vulnerabilities exist in cups More information: The Common UNIX Printing System provides a portable printing layer for UNIX operating systems. It has been developed by Easy Software Products to promote a standard printing solution for all UNIX vendors and users. CUPS provides the System V and Berkeley command-line interfaces. Multiple vulnerabilities have been discovered in cups. Affected Products: - Turbolinux Client 2008 - Turbolinux Appliance Server 3.0 x64 Edition - Turbolinux Appliance Server 3.0 - Turbolinux 11 Server x64 Edition - Turbolinux 11 Server - wizpy - Turbolinux Appliance Server 2.0 - Turbolinux FUJI - Turbolinux 10 Server x64 Edition - Turbolinux Appliance Server 1.0 Hosting Edition - Turbolinux Appliance Server 1.0 Workgroup Edition - Turbolinux 10 Server - Turbolinux Multimedia - Turbolinux Personal Source Packages Size: MD5 http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/turbolinux-source/cups-1.3.7-6.src.rpm 3883765 6a84c95e7afa9f4a53474248c4dbc67a Binary Packages Size: MD5 http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/turbolinux-updates/cups-1.3.7-6.i586.rpm 3453584 bd55ee71c70b1ae3f029c98cc80c5b71 http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/turbolinux-updates/cups-devel-1.3.7-6.i586.rpm 34730 e8b3996e51bb80dd8960d173a6bbf9e1 http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/turbolinux-updates/cups-libs-1.3.7-6.i586.rpm 160249 61b0c64bbc8317778b48838f13c26a8f http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/turbolinux-updates/cups-lpd-1.3.7-6.i586.rpm 19443 4ecf174d43bb019d1600f787b6fe5384 Source Packages Size: MD5 cups-1.3.2-6.src.rpm 4085456 03fc5f9ea6ffa7eb08e09a42e9478aac Binary Packages Size: MD5 cups-1.3.2-6.x86_64.rpm 3582194 1a20adec971c72fe82d581a8da630c3d cups-libs-1.3.2-6.x86_64.rpm 159908 05fecaa38b89f69de853713e22419f39 cups-lpd-1.3.2-6.x86_64.rpm 19487 4b38108abfb6fc04e93dc8d6b73caa87 Source Packages Size: MD5 cups-1.3.2-6.src.rpm 4085456 03fc5f9ea6ffa7eb08e09a42e9478aac Binary Packages Size: MD5 cups-1.3.2-6.i686.rpm 3526419 433af8510b3b8cae1fee801c17b11577 cups-libs-1.3.2-6.i686.rpm 159934 38797fc61849200df7144a975881c73a cups-lpd-1.3.2-6.i686.rpm 19449 90f4c165b12d2d58e67c2f5c9371a7bf Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/11/updates/SRPMS/cups-1.3.2-6.src.rpm 4085456 03fc5f9ea6ffa7eb08e09a42e9478aac Binary Packages Size: MD5 cups-1.3.2-6.x86_64.rpm 3582194 1a20adec971c72fe82d581a8da630c3d cups-devel-1.3.2-6.x86_64.rpm 35804 301b6d13f5897feee4a57c703c4d4d71 cups-libs-1.3.2-6.x86_64.rpm 159908 05fecaa38b89f69de853713e22419f39 cups-lpd-1.3.2-6.x86_64.rpm 19487 4b38108abfb6fc04e93dc8d6b73caa87 Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/11/updates/SRPMS/cups-1.3.2-6.src.rpm 4085456 03fc5f9ea6ffa7eb08e09a42e9478aac Binary Packages Size: MD5 cups-1.3.2-6.i686.rpm 3526419 433af8510b3b8cae1fee801c17b11577 cups-devel-1.3.2-6.i686.rpm 35863 1c9653384a0290896d197a29fd6dcf94 cups-libs-1.3.2-6.i686.rpm 159934 38797fc61849200df7144a975881c73a cups-lpd-1.3.2-6.i686.rpm 19449 90f4c165b12d2d58e67c2f5c9371a7bf Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/wizpy/updates/SRPMS/cups-1.1.23-18.src.rpm 9170287 dad8725761c955bd84a4681a5879b2c8 Binary Packages Size: MD5 cups-1.1.23-18.i386.rpm 7492460 84e2de84bdd560ab160764ba98a223d0 cups-libs-1.1.23-18.i386.rpm 81541 4954fafe55689304190d29b5a360a877 Source Packages Size: MD5 cups-1.1.20-21.src.rpm 4232962 4206f7f09402887b0e1ea51233d745df Binary Packages Size: MD5 cups-1.1.20-21.i586.rpm 2513355 88ecfbf6955ab9a63d14c89f868fe8de cups-devel-1.1.20-21.i586.rpm 128522 ad7de17e37d2ef1ea3d94d418d0dc44b cups-libs-1.1.20-21.i586.rpm 89075 db7d170f625f3e2f3a200089efafa816 Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/11/updates/SRPMS/cups-1.1.23-18.src.rpm 9170287 f38a18ee780c2af2a94da7b610616d98 Binary Packages Size: MD5 cups-1.1.23-18.i686.rpm 8446584 747275f597bf84cacf18d5dd1f69db32 cups-devel-1.1.23-18.i686.rpm 144781 87e3ca973a33ef1eb20e4b0c86d9e902 cups-libs-1.1.23-18.i686.rpm 97260 1b965818f3c3885e2822edcd730657e7 Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/updates/SRPMS/cups-1.1.20-21.src.rpm 4232962 241968e705ebf36671cc185824980fb8 Binary Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/updates/RPMS/cups-1.1.20-21.x86_64.rpm 2510449 5aff07d702578baaa8f900ae7c3745a1 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/updates/RPMS/cups-devel-1.1.20-21.x86_64.rpm 127381 cbcd2d68349d03ccaf2bd018b0139b2f ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/updates/RPMS/cups-libs-1.1.20-21.x86_64.rpm 91849 27a51f51e9bc55e5bca36c004bb1e8d9 Source Packages Size: MD5 cups-1.1.20-21.src.rpm 4233437 72dce88645f44e9cc11eb84cf4175450 Binary Packages Size: MD5 cups-1.1.20-21.i586.rpm 2505102 7e7cf8c0e0e2d59b7111594245751de7 cups-libs-1.1.20-21.i586.rpm 94767 83d12e9a4286642c3d8fb10941b84460 Source Packages Size: MD5 cups-1.1.20-21.src.rpm 4232962 2586ad3745c15e66a806122305d35eb9 Binary Packages Size: MD5 cups-1.1.20-21.i586.rpm 2505287 180c85e884e4a66b65242f90961fbd5c cups-devel-1.1.20-21.i586.rpm 125993 d7469da997c8b1dff4bfecb189b5bc68 cups-libs-1.1.20-21.i586.rpm 94951 b48b5f56bca9c52e79519d5e314a242d Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/updates/SRPMS/cups-1.1.20-21.src.rpm 4232962 4206f7f09402887b0e1ea51233d745df Binary Packages Size: MD5 cups-1.1.20-21.i586.rpm 2513355 88ecfbf6955ab9a63d14c89f868fe8de cups-devel-1.1.20-21.i586.rpm 128522 ad7de17e37d2ef1ea3d94d418d0dc44b cups-libs-1.1.20-21.i586.rpm 89075 db7d170f625f3e2f3a200089efafa816 Source Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/SRPMS/cups-1.1.20-21.src.rpm 4232962 183399bcb33aa5d5226bafa87479ffa4 Binary Packages Size: MD5 ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/cups-1.1.20-21.i586.rpm 2521488 5642c1517f27c4255fea1c2cb96a779c ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/cups-devel-1.1.20-21.i586.rpm 128692 422624ccca7521756f830efe0bebc0bd ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/cups-libs-1.1.20-21.i586.rpm 89262 722310191a74feaea59a7bd8f67eb844 References: CVE [CVE-2008-3639] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3639 [CVE-2008-3640] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3640 [CVE-2008-3641] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3641 -------------------------------------------------------------------------- Revision History 04 Dec 2008 Initial release -------------------------------------------------------------------------- Copyright(C) 2008 Turbolinux, Inc. All rights reserved. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkk3W4IACgkQK0LzjOqIJMzluACgu2dOVDLddZ9CoIXVB5upv/MA FBoAoI/LxreOrHgeNu9SdNaD743DPwzJ =8F2I -----END PGP SIGNATURE-----