Логотип exploitDog
bind:CVE-2024-35235
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-35235

Количество 12

Количество 12

ubuntu логотип

CVE-2024-35235

около 1 года назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group...

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2024-35235

около 1 года назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group...

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-35235

около 1 года назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (n

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2024-35235

7 месяцев назад

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-35235

около 1 года назад

OpenPrinting CUPS is an open source printing system for Linux and othe ...

CVSS3: 4.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2003-1

около 1 года назад

Security update for cups

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2002-1

около 1 года назад

Security update for cups

EPSS: Низкий
rocky логотип

RLSA-2024:4265

около 1 месяца назад

Moderate: cups security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4776

11 месяцев назад

ELSA-2024-4776: cups security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4265

12 месяцев назад

ELSA-2024-4265: cups security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-05605

около 1 года назад

Уязвимость сервера печати CUPS, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 4.4
EPSS: Низкий
redos логотип

ROS-20240806-19

11 месяцев назад

Уязвимость cups

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group...

CVSS3: 4.4
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group...

CVSS3: 4.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (n

CVSS3: 4.4
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 4.4
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and othe ...

CVSS3: 4.4
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2003-1

Security update for cups

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2002-1

Security update for cups

0%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:4265

Moderate: cups security update

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2024-4776

ELSA-2024-4776: cups security update (MODERATE)

11 месяцев назад
oracle-oval логотип
ELSA-2024-4265

ELSA-2024-4265: cups security update (MODERATE)

12 месяцев назад
fstec логотип
BDU:2024-05605

Уязвимость сервера печати CUPS, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 4.4
0%
Низкий
около 1 года назад
redos логотип
ROS-20240806-19

Уязвимость cups

CVSS3: 4.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу