Ubuntu Security Notice 2839-1 - As a security improvement against the POODLE attack, this update disables SSLv3 support in the CUPS web interface. For legacy environments where SSLv3 support is still required, it can be re-enabled by adding "SSLOptions AllowSSL3" to /etc/cups/cupsd.conf.
1962e88312753ed6934b53c14aafc752a3a3f45e659ee785fb483543e0eabbee
============================================================================
Ubuntu Security Notice USN-2839-1
December 16, 2015
cups update
============================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
A security improvement has been made to CUPS.
Software Description:
- cups: Common UNIX Printing System(tm)
Details:
As a security improvement against the POODLE attack, this update disables
SSLv3 support in the CUPS web interface.
For legacy environments where SSLv3 support is still required, it can be
re-enabled by adding "SSLOptions AllowSSL3" to /etc/cups/cupsd.conf.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
cups 1.7.2-0ubuntu1.7
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2839-1
https://launchpad.net/bugs/1505328
Package Information:
https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.7