Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-26691

Опубликовано: 25 мая 2022
Источник: redhat
CVSS3: 6.7

Описание

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

An authorization vulnerability was found in the CUPS printing system. This security vulnerability occurs when local authorization happens. This flaw allows an attacker to authenticate to CUPS as root/admin without the 32-byte secret key and perform arbitrary code execution.

Меры по смягчению последствий

Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux 7cupsNot affected
Red Hat Virtualization 4redhat-virtualization-hostNot affected
Red Hat Enterprise Linux 8cupsFixedRHSA-2022:505615.06.2022
Red Hat Enterprise Linux 8cupsFixedRHSA-2022:505615.06.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionscupsFixedRHSA-2022:505415.06.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportcupsFixedRHSA-2022:505515.06.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportcupsFixedRHSA-2022:505715.06.2022
Red Hat Enterprise Linux 9cupsFixedRHSA-2022:499015.06.2022
Red Hat Enterprise Linux 9cupsFixedRHSA-2022:499015.06.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-288
https://bugzilla.redhat.com/show_bug.cgi?id=2084321cups: authorization bypass when using "local" authorization

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

CVSS3: 6.7
nvd
около 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

CVSS3: 6.7
msrc
около 1 года назад

Описание отсутствует

CVSS3: 6.7
debian
около 3 лет назад

A logic issue was addressed with improved state management. This issue ...

suse-cvrf
около 3 лет назад

Security update for cups

6.7 Medium

CVSS3