安全公告详情

NS-SA-2026-0089

2026-09-07 18:00:00

简介

important: cups-filters/libsoup3 security update

严重级别

important

主题

An update for cups-filters/libsoup3 is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

cups-filters:
libsoup3:


Security Fix(es):
cups-filters: A security vulnerability was found in OpenPrinting CUPS. The function ppdCreatePPDFromIPP2 in the libppd library is responsible for generating a PostScript Printer Description (PPD) file based on attributes retrieved from an Internet Printing Protocol (IPP) response. Essentially, it takes printer information, usually obtained via IPP, and creates a corresponding PPD file that describes the printer's capabilities (such as supported media sizes, resolutions, color modes, etc.). PPD files are used by printing systems like CUPS (Common Unix Printing System) to communicate with and configure printers. They provide a standardized format that allows different printers to work with the printing system in a consistent way. The ppdCreatePPDFromIPP2 function in libppd doesn't properly check or clean IPP attributes before writing them to a temporary PPD file. This means that a remote attacker, who has control of or has hijacked an exposed printer (through UPD or mDNS), could send a harmful IPP attribute and potentially insert malicious commands into the PPD file.(CVE-2024-47175)
cups-filters: bugfix
libsoup3: A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.(CVE-2025-11021)
libsoup3: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • cups-filters
  • libsoup3

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["cups-filters-devel-1.28.17-3.zncgsl7.2.x86_64.rpm","cups-filters-libs-1.28.17-3.zncgsl7.2.x86_64.rpm","cups-filters-1.28.17-3.zncgsl7.2.x86_64.rpm","cups-filters-doc-1.28.17-3.zncgsl7.2.noarch.rpm","cups-filters-braille-1.28.17-3.zncgsl7.2.x86_64.rpm"],"source":"cups-filters-1.28.17-3.zncgsl7.2.src.rpm"},{"binary":["libsoup3-3.6.1-1.zncgsl7.1.x86_64.rpm","libsoup3-doc-3.6.1-1.zncgsl7.1.noarch.rpm","libsoup3-devel-3.6.1-1.zncgsl7.1.x86_64.rpm"],"source":"libsoup3-3.6.1-1.zncgsl7.1.src.rpm"}]}]}

CVE

参考