Scientific Linux Security Update : cups on SL3.x, SL5.x i386/x86_64
High Nessus Plugin ID 60503
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionA NULL pointer dereference flaw was found in the way CUPS handled subscriptions for printing job completion notifications. A local user could use this flaw to crash the CUPS daemon by submitting a large number of printing jobs requiring mail notification on completion, leading to a denial of service. (CVE-2008-5183)
An integer overflow flaw, leading to a heap buffer overflow, was discovered in the Portable Network Graphics (PNG) decoding routines used by the CUPS image-converting filters, 'imagetops' and 'imagetoraster'. An attacker could create a malicious PNG file that could, potentially, execute arbitrary code as the 'lp' user if the file was printed. (CVE-2008-5286)
SolutionUpdate the affected packages.