Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

fstec логотип

BDU:2026-05582

4 месяца назад

Уязвимость сервера печати CUPS, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-34978

4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-34978

4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-34978

4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-34978

4 месяца назад

OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-34978

4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and othe ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2718-1

около 1 месяца назад

Security update for cups

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2732-1

около 1 месяца назад

Security update for cups

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20812-1

2 месяца назад

Security update for cups

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-05582

Уязвимость сервера печати CUPS, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 6.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-34978

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-34978

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34978

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

CVSS3: 6.5
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34978

OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)

CVSS3: 6.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-34978

OpenPrinting CUPS is an open source printing system for Linux and othe ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2718-1

Security update for cups

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2732-1

Security update for cups

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20812-1

Security update for cups

2 месяца назад

Уязвимостей на страницу