diff options
Diffstat (limited to 'meta/recipes-extended/cups/cups/CVE-2023-32360.patch')
-rw-r--r-- | meta/recipes-extended/cups/cups/CVE-2023-32360.patch | 31 |
1 files changed, 31 insertions, 0 deletions
diff --git a/meta/recipes-extended/cups/cups/CVE-2023-32360.patch b/meta/recipes-extended/cups/cups/CVE-2023-32360.patch new file mode 100644 index 0000000000..4d39e1e57f --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2023-32360.patch | |||
@@ -0,0 +1,31 @@ | |||
1 | From a0c8b9c9556882f00c68b9727a95a1b6d1452913 Mon Sep 17 00:00:00 2001 | ||
2 | From: Michael R Sweet <michael.r.sweet@gmail.com> | ||
3 | Date: Tue, 6 Dec 2022 09:04:01 -0500 | ||
4 | Subject: [PATCH] Require authentication for CUPS-Get-Document. | ||
5 | |||
6 | Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/a0c8b9c9556882f00c68b9727a95a1b6d1452913] | ||
7 | CVE: CVE-2023-32360 | ||
8 | Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> | ||
9 | --- | ||
10 | conf/cupsd.conf.in | 8 +++++++- | ||
11 | 1 file changed, 7 insertions(+), 1 deletion(-) | ||
12 | |||
13 | diff --git a/conf/cupsd.conf.in b/conf/cupsd.conf.in | ||
14 | index b258849078..a07536f3e4 100644 | ||
15 | --- a/conf/cupsd.conf.in | ||
16 | +++ b/conf/cupsd.conf.in | ||
17 | @@ -68,7 +68,13 @@ IdleExitTimeout @EXIT_TIMEOUT@ | ||
18 | Order deny,allow | ||
19 | </Limit> | ||
20 | |||
21 | - <Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-My-Jobs Close-Job CUPS-Move-Job CUPS-Get-Document> | ||
22 | + <Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-My-Jobs Close-Job CUPS-Move-Job> | ||
23 | + Require user @OWNER @SYSTEM | ||
24 | + Order deny,allow | ||
25 | + </Limit> | ||
26 | + | ||
27 | + <Limit CUPS-Get-Document> | ||
28 | + AuthType Default | ||
29 | Require user @OWNER @SYSTEM | ||
30 | Order deny,allow | ||
31 | </Limit> | ||