Описание
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
A vulnerability was found in OpenPrinting CUPS. Unauthorized users are permitted to fetch documents over local or remote networks, leading to confidentiality breach.
Отчет
This vulnerability is classified as important according to Red Hat's Severity Rating Classification, as unauthorized users are permitted to fetch documents over local or remote networks, leading to confidentiality breach. https://access.redhat.com/security/updates/classification
Меры по смягчению последствий
The user can either set 'PreserveJobFiles No' in cupsd.conf which will completely shut off the saving the job files, thereby preventing the attacker to get a file or restrict access in firewall and in cupsd to trusted users.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | cups | Out of support scope | ||
Red Hat Enterprise Linux 7 | cups | Fixed | RHSA-2023:4766 | 28.08.2023 |
Red Hat Enterprise Linux 8 | cups | Fixed | RHSA-2023:4864 | 29.08.2023 |
Red Hat Enterprise Linux 8 | cups | Fixed | RHSA-2023:4864 | 29.08.2023 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | cups | Fixed | RHSA-2023:4765 | 28.08.2023 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | cups | Fixed | RHSA-2023:4771 | 28.08.2023 |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | cups | Fixed | RHSA-2023:4771 | 28.08.2023 |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | cups | Fixed | RHSA-2023:4771 | 28.08.2023 |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | cups | Fixed | RHSA-2023:4768 | 28.08.2023 |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | cups | Fixed | RHSA-2023:4768 | 28.08.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
An authentication issue was addressed with improved state management. ...
EPSS
6.5 Medium
CVSS3