Lucene search

K
oraclelinuxOracleLinuxELSA-2024-4265
HistoryJul 02, 2024 - 12:00 a.m.

cups security update

2024-07-0200:00:00
linux.oracle.com
cups
security update
chmod vulnerability
rhel-40386
domain socket
cupsd listener
cve-2024-35235

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

Low

[ - 1:2.2.6-60]

  • RHEL-40386 cups: Cupsd Listen arbitrary chmod 0140777
  • Delete the domain socket file after stopping the cups.socket service
  • Fix cupsd Listener checks
    [1:2.2.6-59]
  • RHEL-40386 cups: Cupsd Listen arbitrary chmod 0140777
  • Require cups.socket in cupsd service file
    [1:2.2.6-58]
  • CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

Low