Описание
Security update for cups
This update for cups fixes the following issues:
- CVE-2025-61915: Fixed local denial-of-service via cupsd.conf update (bsc#1253783)
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
cups-1.7.5-20.57.1
cups-client-1.7.5-20.57.1
cups-devel-1.7.5-20.57.1
cups-libs-1.7.5-20.57.1
cups-libs-32bit-1.7.5-20.57.1
Ссылки
- Link for SUSE-SU-2025:4289-1
- E-Mail link for SUSE-SU-2025:4289-1
- SUSE Security Ratings
- SUSE Bug 1253783
- SUSE CVE CVE-2025-61915 page
Описание
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:cups-1.7.5-20.57.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:cups-client-1.7.5-20.57.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:cups-devel-1.7.5-20.57.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:cups-libs-1.7.5-20.57.1
Ссылки
- CVE-2025-61915
- SUSE Bug 1253783