Re: cups-base problem

2007-11-10 Thread Roland Smith
On Sat, Nov 10, 2007 at 09:41:43PM -0500, Chuck Robey wrote: > Reko Turja wrote: >>> Dear all, >>> >>> Today I saw a security notice: >> ..snip... >>> cat distinfo >>> MD5 (cups-1.3.3-source.tar.bz2) = d4911e68b6979d16bc7a55f68d16cc53 >>> SHA256 (cups-1.3.3-source.tar.bz2) = >>> 5e9e5670777055293

Re: cups-base problem

2007-11-10 Thread Chuck Robey
Reko Turja wrote: Dear all, Today I saw a security notice: ..snip... cat distinfo MD5 (cups-1.3.3-source.tar.bz2) = d4911e68b6979d16bc7a55f68d16cc53 SHA256 (cups-1.3.3-source.tar.bz2) = 5e9e5670777055293e309cb0cbb2758df9c1275bf648df70478b7389c2d804de SIZE (cups-1.3.3-source.tar.bz2) = 40

Re: cups-base problem

2007-11-10 Thread Reko Turja
Dear all, Today I saw a security notice: ..snip... cat distinfo MD5 (cups-1.3.3-source.tar.bz2) = d4911e68b6979d16bc7a55f68d16cc53 SHA256 (cups-1.3.3-source.tar.bz2) = 5e9e5670777055293e309cb0cbb2758df9c1275bf648df70478b7389c2d804de SIZE (cups-1.3.3-source.tar.bz2) = 4077262 Update your

Re: cups-base problem

2007-11-10 Thread Roland Smith
On Sat, Nov 10, 2007 at 10:18:19AM +0100, zbigniew szalbot wrote: > Hello, > > Aryeh M. Friedman pisze: >> > I am not sure I understand the message about remote execution of >> > arbitrary code. >> That is just saying that if the security issue is a problem for you >> don't upgrade (i.e. go ahead

Re: cups-base problem

2007-11-10 Thread zbigniew szalbot
Hello, Aryeh M. Friedman pisze: > Aryeh M. Friedman pisze: >>> I am not sure I understand the message about remote execution >>> of arbitrary code. >> That is just saying that if the security issue is a problem for >> you don't upgrade (i.e. go ahead if you don't care). >> > Thanks but I think I

Re: cups-base problem

2007-11-10 Thread Aryeh M. Friedman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 zbigniew szalbot wrote: > Hello, > > Aryeh M. Friedman pisze: >>> I am not sure I understand the message about remote execution >>> of arbitrary code. >> That is just saying that if the security issue is a problem for >> you don't upgrade (i.e. go ahea

Re: cups-base problem

2007-11-10 Thread zbigniew szalbot
Hello, Aryeh M. Friedman pisze: > I am not sure I understand the message about remote execution of > arbitrary code. That is just saying that if the security issue is a problem for you don't upgrade (i.e. go ahead if you don't care). Thanks but I think I now understand even less :) If a secu

Re: cups-base problem

2007-11-10 Thread Aryeh M. Friedman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > > I am not sure I understand the message about remote execution of > arbitrary code. That is just saying that if the security issue is a problem for you don't upgrade (i.e. go ahead if you don't care). - -- Aryeh M. Friedman Developer, not business

cups-base problem

2007-11-10 Thread zbigniew szalbot
Dear all, Today I saw a security notice: Affected package: cups-base-1.2.11_3 Type of problem: cups -- off-by-one buffer overflow. Reference: