-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2015.3198
                     foomatic-filters security update
                             22 December 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           foomatic-filters
Publisher:         Debian
Operating System:  Debian GNU/Linux 7
                   Debian GNU/Linux 8
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2015-8560 CVE-2015-8327 

Reference:         ESB-2015.3147
                   ESB-2015.3012

Original Bulletin: 
   http://www.debian.org/security/2015/dsa-3429

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-3429-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
December 21, 2015                     https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : foomatic-filters
CVE ID         : CVE-2015-8327 CVE-2015-8560
Debian Bug     : 806886 807993

Michal Kowalczyk and Adam Chester discovered that missing input
sanitising in the foomatic-rip print filter might result in the
execution of arbitrary commands.

For the oldstable distribution (wheezy), these problems have been fixed
in version 4.0.17-1+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 4.0.17-5+deb8u1.

For the unstable distribution (sid), these problems have been fixed in
version 4.0.17-7.

We recommend that you upgrade your foomatic-filters packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWeEE+AAoJEAVMuPMTQ89EMqoP/R0az90cDSfPJdCG534KMRGL
JXgzJsvo8HV7ez4pi/3gJS3uJB1H7oAgsr5DVpn1H7b0ur30NKbxCe+JUoBOWhSw
kSXYBH59v/RFL3y3V253qGDbhpyhFk2iyWOK9OgRfMClLGOQIKWu8wiBxO1BS7wa
OITdatU1UQdRO5beygPRf/JgtIAJ+GMJ+oeUOkRcICpawfIny6IGmgsPiYmZ1nL4
RS8dCqttKYmp92Er0JZSAzUdgC8Br78+IuN1PEir3GohNAFZLGXEIuPgW962VMag
BEqeWATPB1TxLc5Jiw9zaTPD3KNM8kU0N1n3AiONfDRMVCL4XPjZGbTvydLk5eit
MGNs+1PXsfsNZa3Hz9QHd72o+zDL+BjmzZMEklRsMIUQDnz5Vui9Er2CX2kGltYg
9OSwt0gvKyomf0bzTVYbU+oxO3E2Ebg5dhRKJxCgxr9UV0XxOIFmCGbi5G/9r9wT
LjBmx9dZbUp6Pb4dm93LVbLFY5xMHNQ4TYKaOd49C9u+4S3mq/GTs8GWr5mJFFBO
oqJlkMlYsW2xuFNSJibku7HwVR3OYqUAwgiCDtRCroPR/3RPugg/uzPn2eGf16E9
3JiSl9tDTWg0HlntBJy8QFKLrTdi5myuki/OeXvZ/cHFCBs7x+s4sR22J9NaekvS
Zr5vPTs/l5D+x9ri4UnA
=P4XZ
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVnjWTH6ZAP0PgtI9AQLcdg//atAaWNhEcsHAl9/2LkiKN+wTcCUaTEhF
9jmSejTxKQF2jE15UN95XbcOgXQSgOHSKbdruV7Odjw0KJ0t61OBTEp1rFEMMXG8
gTA+Qb+ERf8hV2bl+9tbJ+qn5wCsSg2PFPLbU8XkCL+Y0fbKE+5KBhnEe5YsoJu6
L0WvP+OJgxQyru0D5FESkETHNbQ4qdp6gypMr8/2dNBSQSd7vu2EkHXNZ0hSAH3U
NsNNzgDWvsGI02knEcfUZsT6s/VBbZ98Q++3dJIfK2kRAJNf6RS7j+eAN7XISG+U
JyYw4D2wLYoVKiDhUu/w9ky/HrPPp9hx6NQCcAb3Uy5L9IOug56Edve8D8iEGCfu
o12oyIppa1A3DT1J2Tw4Dl9A764SgxQqfwX9BRGub5Kfpzf/7xQroJp6byOTcZDr
TtuzG5bmw1Cug2HDwhfWUQS3YbaADZvOO0Olpf/I8uM7N6bIFGcffidPOPlVx+PN
OBSdj4qn+0hn4I4/Pjk0E8g0ExxeyOicwrtL3WTyc8W4XC5K39xDDrJkn9z3qvwz
tqz5CnNm3wjeNBNaJPQ24YLlWMHizLkXfOSAvDoUiUKBrV6a2KFoCw6XAAURXvYb
eqbMEUBnzPCk9kFy0m634AeLhNvmIozS21fQz02i0DUIkoSU4L9ywtDk1aS87n99
0hy7CcCVkrg=
=NTkl
-----END PGP SIGNATURE-----