Debian Security Advisory

DLA-1387-1 cups -- LTS security update

Date Reported:
26 May 2018
Affected Packages:
cups
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-18248.
More information:
  • CVE-2017-18248

    It was found that by submitting a print job with an invalid username, the CUPS server can be crashed, when D-Bus support is enabled (which is the case for Debian).

For Debian 7 Wheezy, these problems have been fixed in version 1.5.3-5+deb7u8.

We recommend that you upgrade your cups packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS