gpp_maybe
Security update for cups
SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3261
This update for cups fixes the following issues: - CVE-2024-47175: no validation of IPP attributes in `ppdCreatePPDFromIPP2` when writing to a temporary PPD file allows for the injection of attacker-controlled data to the resulting PPD (bsc#1230932). - CVE-2025-58060: no password check when `AuthType` is set to anything but `Basic` and a request is made with an `Authorization: Basic` header (bsc#1249049). - CVE-2025-58364: unsafe deserialization and validation of printer attributes leads to NULL pointer dereference (bsc#1249128).
-
Release DateSep 18 2025
-
References
-
Typesecurity
-
Severityimportant
cloud_download Downloads
Desktop Applications Module 15.7 x86_64
-
Packagescups
The Common UNIX Printing Systemlibcups2-32bit2.2.7-150000.3.72.1 lock src
HTTP/IPP communication and printer queue and job library2.2.7-150000.3.72.1 lock rpm