[cups] Multiple security fixes in incoming new version 2.4.20
CUPS 2.4.20 will ship multiple security fixes under a revised disclosure policy.
CUPS maintainer Zdenek Dohnal said the upcoming 2.4.20 release contains multiple security fixes. Because of report volume and CVE assignment delays, flaws scoring above CVSS 7.0 will be embargoed, while lower-scoring issues will be fixed and published immediately under GHSA identifiers. The message names no CVE IDs and does not report exploitation.
- CUPS 2.4.20 will include multiple security fixes.
- Issues above CVSS 7.0 stay embargoed until announcement.
- Lower-severity issues use GHSA IDs and are fixed without embargo.
- No specific CVE IDs are named in the note.
Posted by Zdenek Dohnal on Oct 05 Hi all! due heavy load of security reports and long queues of Github CNA we had re-evaluate our security policies to the following points: - we do embargoes for vulnerabilities with CVSS score > 7.0, which will be announced on proper security lists - we use GHSA ids for vulnerabilities under CVSS score 7.0, and we commit the fix and publish the advisory without embargo - this point was applied because of long queue for getting CVE id...
This source does not provide full text. Read it at seclists.org.