USN-4340-1: CUPS vulnerabilities

27 April 2020

Several security issues were fixed in CUPS.

Releases

Packages

  • cups - Common UNIX Printing System(tm)

Details

It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)

Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04
Ubuntu 19.10
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.