From nobody Wed Oct 02 09:29:12 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4XJTyw5ZbZz5YFwF; Wed, 02 Oct 2024 09:29:12 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4XJTyw529Qz4vhM; Wed, 2 Oct 2024 09:29:12 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1727861352; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=fgJNgD44uIDyg4YTGu7JC5/MuKYzN+hcqRXwp9vfsQ4=; b=Hgl0V0X9AF6wdWguQSAL3fRTZF7LoVfNOdsfO/PVgavzk4Ahd4WLMoeFV4PbKn/iC2mlKO IhepAm0O3hsvf3NnlQK5l3jeu5H9xR2bGVmuiiG16rKefB6DUzTQiUsahSlxPle8m59F7b 4f/v9GGmU2XZWEoHiCPuQbbrIn9yoGAEdLUVtWD2tqDHOR7rX/EbmXHqQezNX8E+KOxZzu R8gwa9ZPA3g/8Pjawcytrs1bZUVfarMwCTUJwW+804tzwbHd++AMsqJ3jzPVWmnW9rSI8h 2U+/+MsEoZgIKosaxhZb8/ktcGbH1J2WFuBgLM35d5EPwdq5IBdrPcqh1andGg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1727861352; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=fgJNgD44uIDyg4YTGu7JC5/MuKYzN+hcqRXwp9vfsQ4=; b=oufqlWF4Q9iKNnpv1myRiVFfS/2PjT5dLQ4auxY5FpM2YEMt5RA8SmWXgXRdxRuYrCTYCa ofSJQXDnmbnGTGAMW21MrPVI1+YshOpxdc33cKkPLDveUs8U3Q1eU4B02VGGMMerDlXFFj CJAwnv2O2VmgJLM7WSWWzdIQ48zIseQ2jSQH4GmxFvxlA+GZP743sueGMmr1IzYJS5G8mc 8nptRKHnrEHB9Xs+6+q6hm9/S/jZFS/0YXspnKgXE0+Ziu655lmqHfbkuvWgz5Ot0LQuvv Hs2QkP3RzHVy9odtQtw1C5c/0Q6ub7FQcNHGIiyoJ75oYhJjrPQvcZHimhwinQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1727861352; a=rsa-sha256; cv=none; b=dKLiIMYgSEJUTe8Gi9UJQ400OC6TVfS3q9IojM+qICT/3jeoIWcVzIk+uZcRuR9zJPqyMo VNbQqIA0UmXbfV8s0rAWXONi4D/22DriCqxxfEStwRtGiicRSnHnxdmzPqp/anE5MFaZHN imYhXGkmptx5FGf6hDKMosGLpP4o4a2NmxbORkwPkdYjcID9HOLOSNAvhoIIATEeavu7iO IXaiU2ZctZNd8HXFpta6Ho/RRbp+aPgcR/djZEEIbmKeKp8LzspmzWZ9Wx7PmCoIC3daNh 0i/TIU2RLOHFgJAUmPq78F5Ef9VuS8H03/PQXPHx49Y3s+oWaqOLzZagW+u5CA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4XJTyw4f99z1F8c; Wed, 2 Oct 2024 09:29:12 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 4929TCXd089927; Wed, 2 Oct 2024 09:29:12 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 4929TCr0089924; Wed, 2 Oct 2024 09:29:12 GMT (envelope-from git) Date: Wed, 2 Oct 2024 09:29:12 GMT Message-Id: <202410020929.4929TCr0089924@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Tijl Coosemans Subject: git: c391dd71c614 - main - security/vuxml: Update cups-filters entry List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: tijl X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: c391dd71c614d9a6be09b7cf19c98a87685c53fc Auto-Submitted: auto-generated The branch main has been updated by tijl: URL: https://cgit.FreeBSD.org/ports/commit/?id=c391dd71c614d9a6be09b7cf19c98a87685c53fc commit c391dd71c614d9a6be09b7cf19c98a87685c53fc Author: Tijl Coosemans AuthorDate: 2024-10-02 09:26:16 +0000 Commit: Tijl Coosemans CommitDate: 2024-10-02 09:28:09 +0000 security/vuxml: Update cups-filters entry --- security/vuxml/vuln/2024.xml | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index f3ed777ed074..1cbd1a92f881 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -110,7 +110,11 @@ cups-filters - 0 + 1.28.17_6 + + + cups + 2.4.11 @@ -139,14 +143,14 @@

# service cups_browsed status
# service cups_browsed stop
# service cups_browsed disable

-

Attacks from the internet can be blocked by removing the "cups" - protocol from the BrowseRemoteProtocols and BrowseProtocols - directives in /usr/local/etc/cups/cups-browsed.conf. Attacks using - mDNS can be blocked by removing the "dnssd" protocol as well. Access - can be limited to specific IP addresses using BrowseAllow, - BrowseDeny, and BrowseOrder directives as documented in - cups-browsed.conf(5). Then restart the service with the following - command:

+

If you choose to leave the service enabled, attacks from the + internet can be blocked by removing the "cups" protocol from the + BrowseRemoteProtocols and BrowseProtocols directives in + /usr/local/etc/cups/cups-browsed.conf. Attacks using mDNS can be + blocked by removing the "dnssd" protocol as well. Access can be + limited to specific IP addresses using BrowseAllow, BrowseDeny, and + BrowseOrder directives as documented in cups-browsed.conf(5). Then + restart the service with the following command:

# service cups_browsed restart

@@ -154,12 +158,12 @@ CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 - CVE-2024-47177 https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8 2024-09-26 2024-09-27 + 2024-10-02