Bug 866302 (CVE-2013-6473) - VUL-1: cups-filters: several security issues
Summary: VUL-1: cups-filters: several security issues
Status: RESOLVED FIXED
Alias: CVE-2013-6473
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Johannes Meixner
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-28 13:59 UTC by Marcus Meissner
Modified: 2014-03-27 08:12 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Swamp Workflow Management 2014-02-28 23:00:35 UTC
bugbot adjusting priority
Comment 3 Marcus Meissner 2014-03-11 15:33:35 UTC
CVE-2013-6476:
CVE-2013-6475: 
CVE-2013-6474:
fix:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7176


CVE-2013-6473:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7175


Reviewing that I am not convinced we need an update right now for SLE.

-> planned
Comment 4 Marcus Meissner 2014-03-11 15:38:21 UTC
also cups on SLE11 does not contain OPVP or urftopdf at all, so SUSE LInux Enterprise is not affected.
Comment 5 Johannes Meixner 2014-03-11 16:07:07 UTC
I change the bug's subject from
"cups: cups-filters: several security issues"
to
"cups-filters: several security issues"
because cups-filters is not part of CUPS.

cups-filters is a separated source package that is currently
nowhere distributed in any SUSE or openSUSE product.

Currently SUSE is not at all affected.
Comment 9 Johannes Meixner 2014-03-27 08:12:36 UTC
The issue is fixed since cups-filters 1.0.47
see its NEWS file entry:
---------------------------------------------------------------------------
        - pdftoopvp: SECURITY FIX for CVE-2013-6474, CVE-2013-6475,
          and CVE-2013-6476: Introductionof gmallocn and gmallocn3
          to protect against arbitrary code execution with the
          privileges of the "lp" user via malicious PDF files. Also
          restrict the directory from where OPVP drivers can get
          loaded.
        - urftopdf: SECURITY FIX for CVE-2013-6473: Two heap-based
          buffer overflow flaws in urftopdf. If a malicious URF file
          were processed it could lead to arbitrary code execution
          with the privileges of the "lp" user.
---------------------------------------------------------------------------

cups-filters 1.0.49 submitted and accepted in its devel project "Printing"
via OBS submitrequest 227590 and forwarded to openSUSE:Factory
via OBS submitrequest 227591.