desktop-packages team mailing list archive
-
desktop-packages team
-
Mailing list archive
-
Message #142876
[Bug 1505328] [NEW] Cups SSL is vulernable to POODLE
*** This bug is a security vulnerability ***
Public security bug reported:
On 12.04 and 14.04 if you enable cups ssl you are vulnerable to poodle,
and there does not appear to be any way to mitigate it in Cups config.
Ubuntu 14.04 - https://www.ssllabs.com/ssltest/analyze.html?d=190.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Ubuntu 12.04 - https://www.ssllabs.com/ssltest/analyze.html?d=191.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Fixed in wily - https://www.ssllabs.com/ssltest/analyze.html?d=192.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Upstream fix - https://www.cups.org/str.php?L4476
Should we disable ssvl3 in the 12.04/14.04 cups by default and backport
the option to turn it back on?
** Affects: cups (Ubuntu)
Importance: Undecided
Status: New
** Information type changed from Public to Public Security
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to cups in Ubuntu.
https://bugs.launchpad.net/bugs/1505328
Title:
Cups SSL is vulernable to POODLE
Status in cups package in Ubuntu:
New
Bug description:
On 12.04 and 14.04 if you enable cups ssl you are vulnerable to
poodle, and there does not appear to be any way to mitigate it in Cups
config.
Ubuntu 14.04 - https://www.ssllabs.com/ssltest/analyze.html?d=190.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Ubuntu 12.04 - https://www.ssllabs.com/ssltest/analyze.html?d=191.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Fixed in wily - https://www.ssllabs.com/ssltest/analyze.html?d=192.35.213.162.lcy-02.canonistack.canonical.com&hideResults=on
Upstream fix - https://www.cups.org/str.php?L4476
Should we disable ssvl3 in the 12.04/14.04 cups by default and
backport the option to turn it back on?
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cups/+bug/1505328/+subscriptions
Follow ups
-
[Bug 1505328] Re: Cups SSL is vulnerable to POODLE
From: Marc Deslauriers, 2015-12-16
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Launchpad Bug Tracker, 2015-12-16
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Marc Deslauriers, 2015-12-11
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-12-08
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Marc Deslauriers, 2015-12-08
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Brian Murray, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Mathew Hodson, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-17
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-12
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Marc Deslauriers, 2015-11-10
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Marc Deslauriers, 2015-11-10
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Mathew Hodson, 2015-11-09
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Ubuntu Foundations Team Bug Bot, 2015-11-02
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-02
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-02
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-11-02
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-29
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-26
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-23
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-23
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-23
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Bryan Quigley, 2015-10-20
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Seth Arnold, 2015-10-13
-
[Bug 1505328] Re: Cups SSL is vulernable to POODLE
From: Thomas Ward, 2015-10-12