From: Johannes Meixner <jsmeix@suse.de>
To: Till Kamppeter <till.kamppeter@gmail.com>
Cc: Zdenek Dohnal <zdohnal@redhat.com>,
OpenPrinting <printing-architecture@lists.linux.dev>
Subject: Re: CUPS 2.4.11 is released!
Date: Mon, 30 Sep 2024 16:55:08 +0200 [thread overview]
Message-ID: <aabd2b8c27f7c075ef169f49c4f70f7f@suse.de> (raw)
In-Reply-To: <99331637-44cc-48d1-8323-bd89f0579aba@gmail.com>
Hello,
On 2024-09-30 16:42, Till Kamppeter wrote:
> thanks for the quick release, but the CHANGES.md
> does not mention the CVE-related fixes contained in it.
> On 9/30/24 14:25, Zdenek Dohnal wrote:
>> CUPS 2.4.11 brings several bug fixes
>> regarding IPP response validation, processing PPD values,
>> Web UI support (checkbox support, modifying printers)
>> and others fixes.
I was also wondering about CVE-related fixes.
As far as I understand it from the GitHub upstream commits
CUPS 2.4.11 contains (only) those commits regarding
IPP response validation and processing PPD values
"Quote PPD localized strings"
https://github.com/OpenPrinting/cups/commit/1e6ca5913eceee906038bc04cc7ccfbe2923bdfd
plus the cleanup to "Fix warnings for unused vars"
https://github.com/OpenPrinting/cups/commit/2abe1ba8a66864aa82cd9836b37e57103b8e1a3b
which are somewhat related to those CVEs
by avoiding sililar further issues as in those CVEs
but are not the actual fixes for explicitly those CVEs.
Kind Regards
Johannes Meixner
--
SUSE Software Solutions Germany GmbH
Frankenstr. 146 - 90461 Nuernberg - Germany
(HRB 36809, AG Nuernberg) GF: Ivo Totev
next prev parent reply other threads:[~2024-09-30 14:55 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-30 12:25 CUPS 2.4.11 is released! Zdenek Dohnal
2024-09-30 14:42 ` Till Kamppeter
2024-09-30 14:53 ` Mike Sweet
2024-09-30 14:55 ` Johannes Meixner [this message]
2024-10-01 6:28 ` Zdenek Dohnal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aabd2b8c27f7c075ef169f49c4f70f7f@suse.de \
--to=jsmeix@suse.de \
--cc=printing-architecture@lists.linux.dev \
--cc=till.kamppeter@gmail.com \
--cc=zdohnal@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.