Lucene search

K
ubuntuUbuntuUSN-6844-2
HistoryJun 28, 2024 - 12:00 a.m.

CUPS regression

2024-06-2800:00:00
ubuntu.com
ubuntu
cups
printing

7.5 High

AI Score

Confidence

Low

Releases

  • Ubuntu 24.04 LTS
  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • cups - Common UNIX Printing System™

Details

USN-6844-1 fixed vulnerabilities in the CUPS package. The update
lead to the discovery of a regression in CUPS with regards to
how the cupsd daemon handles Listen configuration directive.
This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:
Rory McNamara discovered that when starting the cupsd server with a
Listen configuration item, the cupsd process fails to validate if
bind call passed. An attacker could possibly trick cupsd to perform
an arbitrary chmod of the provided argument, providing world-writable
access to the target.

OSVersionArchitecturePackageVersionFilename
Ubuntu24.04noarchcups< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-bsd< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-bsd-dbgsym< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-client< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-client-dbgsym< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-common< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-core-drivers< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-core-drivers-dbgsym< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-daemon< 2.4.7-1.2ubuntu7.2UNKNOWN
Ubuntu24.04noarchcups-daemon-dbgsym< 2.4.7-1.2ubuntu7.2UNKNOWN
Rows per page:
1-10 of 1571

7.5 High

AI Score

Confidence

Low