Opened 8 weeks ago
Closed 6 weeks ago
#23707 closed enhancement (fixed)
libcupsfilters-2.2.0 (Security Update)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | normal | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New minor version.
Change History (5)
comment:1 by , 7 weeks ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 7 weeks ago
| Summary: | libcupsfilters-2.2.0 → libcupsfilters-2.2.0 (Security Update) |
|---|
comment:3 by , 7 weeks ago
It looks like we can remove qpdf and will need to replace it with pdfio.
https://github.com/michaelrsweet/pdfio/releases/download/v1.6.4/pdfio-1.6.4.tar.gz
./configure --prefix=/usr \
--disable-static \
--enable-shared
make
make install
libpng is optional but should probably be recommended.
docdir is not honored. Need to 'mv /usr/share/doc/pdfio /usr/share/doc/pdfio-1.6.4' manually.
comment:4 by , 7 weeks ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:5 by , 6 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-197 has been issued.
Note:
See TracTickets
for help on using tickets.

CHANGES IN V2.2.0 (6th August 2026)
cfFilterPDFToPDF(),cfFilterPCLmToRaster(),cfFilterPWGToPDF(),cfFilterBannerToPDF(). Also turned the code from C++ into C.cfFilterPDFToRaster()replaced use of libpoppler by using PDFio and also the external executablepdftoppmof poppler-utils, Also here turned C++ code into C.cupsfilters/test-filter-cases.txt.cfFilterTextToPDF()FC_MONOconstraint to allow proportional fonts. Some languages have non-monospaced scripts and now they can correctly load their intended fonts.cfFilterTextToPDF()expects UTF-8 input by default now.cfFilterGhostscript()introducedcupsHalftoneTypedithering algorithms. Controlled withhalftone-typejob option orcupsHalftoneTypePPD option. Added stochastic halftoning, bi-level threshold, and an algorithm from foo2zjs, 8x8, genordered, and spot from PDFmake checkand also Debian's autopkgtests as unit testspdftopdfvalidationtestfiltersjust go through all lines of test cases instead of using line count as a parameterFilterChain()support totestfilters. Manually providing a filter chain is optional, if not supplied, it is set automatically as before*-supported/*-defaultattributes, in thecfIPPAttrEnumValForPrinter()function. Check IPP tags (data types) to avoid NULL derefencescfGetBackSideOrientation()andcfGetPrintRenderIntent()look up several IPP attributes. Also here check tags/data types to avoid NULL derefencescfFilterPDFToRaster()if PDF has too large page dimensions. Crop dimensions to maximum allowed by standard, 14400x14400pt, 200x200in, 5x5m, if needed. (CVE-2025-64503) ModeratecfImageLutcfFilterImageTo...(): Added error handling for libpng and libjpeg function calls to avoid the process being aborted. (CVE-2026-64612)NormalizeMakeModelwhen manufacturer name too longpdftoraster,gsto...,mupdftopwg: Fix NULL-pointer dereference when parsing%%PDFTOPDF...commentspdftoraster: Check result ofrender_page()as it may return NULL if the page is not properly constructedimagetopdf: convert custom media sizemin_widthandmin_heightto pointscfFilterChain(): Initialize return value to 0. In some cases the function exits with non-zero status when all filters exit with no errors (zero status).cupsParseOptions()cups_media_sif running a version older then CUPS 2.5.xtestfilters.cto use CUPS 3.0 API with compatibility shim for CUPS 2.x and older. Given that this is an end-user program, we don't want to includelibcups2-private.h. Also tweaked Makefile to link against proper CUPS library.cups/backend.h../configureoption. When building without fontconfig,cfFilterTextToPDF()gets no-op (to keep API)./configureoption-with-cjk-fontssets alternative namesys/stat.hinclude for Solaris/bin/shfortestfilters.shto avoid dependency on bashcfFilterImageToPDF(): Added extra debug log messages concerning page orientation