Debian Security Advisory
DSA-2876-1 cups -- security update
- Date Reported:
- 12 Mar 2014
- Affected Packages:
- cups
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2013-6474, CVE-2013-6475, CVE-2013-6476.
- More information:
-
Florian Weimer of the Red Hat Product Security Team discovered multiple vulnerabilities in the pdftoopvp CUPS filter, which could result in the execution of aribitrary code if a malformed PDF file is processed.
For the oldstable distribution (squeeze), these problems have been fixed in version 1.4.4-7+squeeze4.
For the stable distribution (wheezy) and the unstable distribution (sid) the filter is now part of the cups-filters source package.
We recommend that you upgrade your cups packages.