<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="b9517c6deeb9b6fb02cdb512c1c8745c"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="3574">
  <id>dbg111-cups</id>
  <title>cups: security update</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1290619546"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=649256" id="649256" title="bug number 649256" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2941" id="CVE-2010-2941" title="CVE-2010-2941" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0542" id="CVE-2010-0542" title="CVE-2010-0542" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748" id="CVE-2010-1748" title="CVE-2010-1748" type="cve"/>
  </references>
  <description>This updates fix several bugs, but only the security fixes
are listed here:
- CVE-2010-2941: CVSS v2 Base Score: 3.3
  (AV:A/AC:L/Au:N/C:N/I:N/A:P): CWE-399 Special IPP
  requests allow to crashcupsd remotely.
- CVE-2010-0542: CVSS v2 Base Score: 6.8
  (AV:N/AC:M/Au:N/C:P/I:P/A:P): CWE-264 A NULL pointer
  dereference exists in the _WriteProlog() function of the
  texttops image filter.
- CVE-2010-1748: CVSS v2 Base Score: 4.3
  (AV:N/AC:M/Au:N/C:P/I:N/A:N): CWE-119 An attacker with
  access to the web-interface may be able to read some
  bytes of uninitialized memory.
</description>
  <pkglist>
    <collection>
        <package name="cups-debuginfo" arch="i586" version="1.3.9" release="7.10.1">
          <filename>cups-debuginfo-1.3.9-7.10.1.i586.rpm</filename>
        </package>
        <package name="cups-debuginfo" arch="ppc" version="1.3.9" release="7.10.1">
          <filename>cups-debuginfo-1.3.9-7.10.1.ppc.rpm</filename>
        </package>
        <package name="cups-debuginfo" arch="x86_64" version="1.3.9" release="7.10.1">
          <filename>cups-debuginfo-1.3.9-7.10.1.x86_64.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="i586" version="1.3.9" release="7.10.1">
          <filename>cups-debugsource-1.3.9-7.10.1.i586.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="ppc" version="1.3.9" release="7.10.1">
          <filename>cups-debugsource-1.3.9-7.10.1.ppc.rpm</filename>
        </package>
        <package name="cups-debugsource" arch="x86_64" version="1.3.9" release="7.10.1">
          <filename>cups-debugsource-1.3.9-7.10.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
