Lucene search

K
nessusThis script is Copyright (C) 2024 and is owned by Tenable, Inc. or an Affiliate thereof.ROCKY_LINUX_RLSA-2024-7346.NASL
HistorySep 30, 2024 - 12:00 a.m.

Rocky Linux 9 : cups-filters (RLSA-2024:7346)

2024-09-3000:00:00
This script is Copyright (C) 2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
rocky linux 9
cups-browsed
cups-filters
rlsa-2024
cve-2024-47076
remote command injection

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

9.2

Confidence

High

The remote Rocky Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2024:7346 advisory.

* cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source ()

* cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP     attributes (CVE-2024-47076)

* cups: libppd: remote command injection via attacker controlled data in PPD file ()

Tenable has extracted the preceding description block directly from the Rocky Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.

File data rocky_linux_RLSA-2024-7346.nasl

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

9.2

Confidence

High