cups-2.3.3op2-27.el9_4
エラータID: AXSA:2024-8601:06
リリース日:
2024/07/26 Friday - 18:17
題名:
cups-2.3.3op2-27.el9_4
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- CUPS の cupsd には、Listen 設定値にシンボリックリンク
が設定されている状態で cupsd を起動した際、指定した引数
で chmod コマンドを実行し、意図しないアクセス権限を付与
してしまう問題があるため、ローカルの攻撃者により、不正
なファイルの書き込み、および情報の漏洩を可能とする脆弱性
が存在します。(CVE-2024-35235)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-35235
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.
追加情報:
N/A
ダウンロード:
SRPMS
- cups-2.3.3op2-27.el9_4.src.rpm
MD5: 5d2c7d5b310db61a9a92f7846152943b
SHA-256: d1fc2ee1bd9f3f5fd4f5075a9824bbd6ce9ff9e85995d2131f4cc625f068dfb4
Size: 7.74 MB
Asianux Server 9 for x86_64
- cups-2.3.3op2-27.el9_4.x86_64.rpm
MD5: d76118f528f6e5022f3b209f673c9680
SHA-256: 8a1f6e5e35ce1bb604ff45b52c84c087806ea22e9dc74135842c84bc11861018
Size: 1.47 MB - cups-client-2.3.3op2-27.el9_4.x86_64.rpm
MD5: 159a12d0d9892411a37f62216fb8e12b
SHA-256: 39dae95029eb8f5ac43b19ed364e37121cc2baec3c4fcf12d20132ff84fc4d57
Size: 73.04 kB - cups-devel-2.3.3op2-27.el9_4.i686.rpm
MD5: 34741b61cca904d4948a7d7c92bd281a
SHA-256: c2fc4ba3ea9c032b0fd3e802c17e775d280d989a69a7cbefdb8ae927fe07faa0
Size: 52.72 kB - cups-devel-2.3.3op2-27.el9_4.x86_64.rpm
MD5: fd34e9346b6154d6f84840a7c349e0cd
SHA-256: cdc303dcf78cf5c0be903121fd94feba24a3dafb81388baac8f153c890bb06c1
Size: 52.73 kB - cups-filesystem-2.3.3op2-27.el9_4.noarch.rpm
MD5: aa5bd309fccccde34dbf801c705eb534
SHA-256: c18e1b373b1280cfca4002855f6bed4cd2cd0ab9f2a7003384988844933a0895
Size: 9.52 kB - cups-ipptool-2.3.3op2-27.el9_4.x86_64.rpm
MD5: 3ee02a7a9b16f212799ba072a3fcc6a9
SHA-256: dd69cf650622d7a3acfc4d232534eb4105327ea8fa3405f9ee88696c4e886052
Size: 3.87 MB - cups-libs-2.3.3op2-27.el9_4.i686.rpm
MD5: a5a28c8b33204c5e7b26642e59f6153d
SHA-256: 0fd3491e8c3a88092b08bbf085f7268b371789e6893207c39126b9c962af0be7
Size: 278.85 kB - cups-libs-2.3.3op2-27.el9_4.x86_64.rpm
MD5: 89910074ad6d3de1879aef81bf5428b7
SHA-256: 103dd0cd30648419b9c0b0d93f342959ed68cadda9b7ead858741ed230dae264
Size: 260.58 kB - cups-lpd-2.3.3op2-27.el9_4.x86_64.rpm
MD5: e5480045224d9f08ee79476086f3ab28
SHA-256: 58c8d7e862d26f4f38ed459af050d5ffcfe785bfd26a0a9afe79567385e8cb0d
Size: 24.57 kB - cups-printerapp-2.3.3op2-27.el9_4.x86_64.rpm
MD5: 1a94e2da9b28ca02183facc427af7656
SHA-256: f7cb65ce59ca8b00ee5a548db457df213351aa3bc7cf7a9f9779be42008a882b
Size: 113.89 kB