-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.6
Date: Fri, 17 Jan 2003 13:50:33 -0500
Source: cupsys
Binary: cupsys-bsd libcupsys1 cupsys libcupsys1-dev
Architecture: arm
Version: 1.0.4-12.1
Distribution: oldstable-security
Urgency: high
Maintainer: Debian/ARM Build Daemon <buildd@europa.debian.org>
Description: 
 cupsys     - Common UNIX Printing System(tm) - base
 cupsys-bsd - Common UNIX Printing System(tm) - BSD commands
 libcupsys1 - Common UNIX Printing System(tm) - libs
 libcupsys1-dev - Common UNIX Printing System(tm) - development files
Changes: 
 cupsys (1.0.4-12.1) oldstable-security; urgency=high
 .
   * Security team NMU
   * Fix bugs reported in iDEFENSE advisory
     http://www.idefense.com/advisory/12.19.02.txt
     - [issue 1] patch integer overflows in image handling code
       (filter/image-*.c)
     - [issue 2] not applicable to this version
     - [issue 3] check for invalid URIs in browse packets
       (scheduler/dirsvc.c)
     - [issue 4] protect against negative length memcpy calls
       (scheduler/client.c, cups/http.c)
     - [issue 5] fix unsafe strncat calls
       (scheduler/job.c)
     - [issue 6] add check for zero-{width,height} GIF image
       (filter/image-gif.c)
     - [issue 7] detect errors and close file descriptors appropriately
       (scheduler/client.c)
   * Fix other instances of incorrect strncat usage
     (scheduler/client.c, scheduler/dirsvc.c,
      scheduler/log.c)
   * Include additional fixes from Debian maintainer, Jeff Licquia
     <licquia@debian.org>
     - Recover from file descriptor DoS more gracefully
     - Fix from upstream to return status indicating whether
       CloseClient was called, to prevent further processing
     - add missing CloseClient call which caused DoS to be
       re-introduced by above patch
Files: 
 eb5abc77ec982a103cb99fd1ae44fb8e 2335642 net extra cupsys_1.0.4-12.1_arm.deb
 cac8881dd707af979bcc3b2c0774f7ad 64726 net extra libcupsys1_1.0.4-12.1_arm.deb
 f493560542d625644d3675fbf31a5c32 92574 net extra libcupsys1-dev_1.0.4-12.1_arm.deb
 54db853e04f164bdb6f7c3780a770f45 17042 net extra cupsys-bsd_1.0.4-12.1_arm.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+Kn6ZW5ql+IAeqTIRAiaaAKCOwgwpmUjeX4GPm8axAmWbxoaezgCeLPqS
aP33vC7QMJ9KNrAFc1SAHeI=
=8P9b
-----END PGP SIGNATURE-----