Summary
The remote host is missing updates announced in
advisory GLSA 201207-10.
Solution
All CUPS users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-print/cups-1.4.8-r1'
NOTE: This is a legacy GLSA. Updates for all affected architectures are available since September 03, 2011. It is likely that your system is already no longer affected by this issue.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201207-10 http://bugs.gentoo.org/show_bug.cgi?id=295256
http://bugs.gentoo.org/show_bug.cgi?id=308045
http://bugs.gentoo.org/show_bug.cgi?id=325551
http://bugs.gentoo.org/show_bug.cgi?id=380771
Insight
Multiple vulnerabilities have been found in CUPS, some of which may allow execution of arbitrary code or local privilege escalation.
Severity
Classification
-
CVE CVE-2009-3553, CVE-2010-0302, CVE-2010-0393, CVE-2010-0540, CVE-2010-0542, CVE-2010-1748, CVE-2010-2431, CVE-2010-2432, CVE-2010-2941, CVE-2011-3170 -
CVSS Base Score: 7.9
AV:A/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities