Release date:
2026-08-04 23:38:13 UTC
Description:
* SECURITY UPDATE: authentication bypass via alternate auth method
- debian/patches/CVE-2025-58060.patch: only validate Basic credentials
when the resource requires Basic auth, and only process Negotiate when
it requires Kerberos, in scheduler/auth.c cupsdAuthorize(); backport of
upstream commit 595d691075b1d396d2edfaa0a8fd0873a0a1f221
- CVE-2025-58060
Updated packages:
-
cups_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:fed4dde2101f355d413bd92b249e223be3b070ca
-
cups-bsd_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:b74060a31053f3f1c6d02b1b15b4bea23a91b448
-
cups-client_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:bbcb2edb8cca6155d81444b7db784f46fd354324
-
cups-common_2.3.1-9ubuntu1.9+tuxcare.els3_all.deb
sha:6a27ed1961a89205ba76b84f036b3a40fe40492e
-
cups-core-drivers_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:fbbf5440a6f2fed1ed018ec9edea77e3c4a6e4e3
-
cups-daemon_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:1bb09a3b8f2c2d2b2e6ec72a315e52f3bc63b1f4
-
cups-ipp-utils_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:7354c5585a6c5b8396cc1f9d43b24947703d6186
-
cups-ppdc_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:507b9d80cfd5b5eff0ba242d87500353e0e45c1e
-
cups-server-common_2.3.1-9ubuntu1.9+tuxcare.els3_all.deb
sha:14679bcc364654799fd351cae05d2da8c3f38ffc
-
libcups2_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:5d51c064e31775fe4f37e33c715f1b994d5a8b3e
-
libcups2-dev_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:10d8fa6f10994ed7ce4f6d08c32196b67206dce0
-
libcupsimage2_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:095875831fe5c790a8813c9cff73b9d6e31e22e8
-
libcupsimage2-dev_2.3.1-9ubuntu1.9+tuxcare.els3_amd64.deb
sha:4af1ef8b761a841a90a52adfd8b07da51aa4518b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.