<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="e1ef8955282f1a32cf0d3c4a50d75a32"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2102">
  <id>dbg111-cups</id>
  <title>cups security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1265819912"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=574336" id="574336" title="bug number 574336" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=578215" id="578215" title="bug number 578215" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0393" id="CVE-2010-0393" title="CVE-2010-0393" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0302" id="CVE-2010-0302" title="CVE-2010-0302" type="cve"/>
  </references>
  <description>lppasswd when running setuid or setgid still honors
environment variables that specify the location of message
files. Local attackers could exploit that to gather
information by using crafted format strings (CVE-2010-0393).

The previous fix for a use-after-free vulnerability
(CVE-2009-3553) was incomplete (CVE-2010-0302).
</description>
  <pkglist>
    <collection>
        <package name="cups-debuginfo" arch="i586" version="1.3.9" release="7.8.1">
          <filename>cups-debuginfo-1.3.9-7.8.1.i586.rpm</filename>
        </package>
        <package name="cups-debuginfo" arch="ppc" version="1.3.9" release="7.8.1">
          <filename>cups-debuginfo-1.3.9-7.8.1.ppc.rpm</filename>
        </package>
        <package name="cups-debuginfo" arch="x86_64" version="1.3.9" release="7.8.1">
          <filename>cups-debuginfo-1.3.9-7.8.1.x86_64.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="i586" version="1.3.9" release="7.8.1">
          <filename>cups-debugsource-1.3.9-7.8.1.i586.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="ppc" version="1.3.9" release="7.8.1">
          <filename>cups-debugsource-1.3.9-7.8.1.ppc.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="x86_64" version="1.3.9" release="7.8.1">
          <filename>cups-debugsource-1.3.9-7.8.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
