cups-1.6.3-52.0.3.el7.AXS7

エラータID: AXSA:2025-11105:08

リリース日: 
2025/11/26 Wednesday - 10:10
題名: 
cups-1.6.3-52.0.3.el7.AXS7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

CUPS printing system provides a portable printing layer for
UNIX® operating systems. It has been developed by Apple Inc.
to promote a standard printing solution for all UNIX vendors and users.
CUPS provides the System V and Berkeley command-line interfaces.

Security Fix(es):

* CVE-2024-35235: patch arbitrary chmod vulnerability in cupsd process when
starting server with symbolic link Listen configuration item

CVE(s):
CVE-2024-35235
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

Asianux Server 7 for x86_64
  1. cups-1.6.3-52.0.3.el7.AXS7.x86_64.rpm
    MD5: 696fa49ad70b8d1d7cbc15829449bb00
    SHA-256: 9697087e78c4dc76f79069642e9ec1ffd1bfa44a6c1a4638dd7070bde4e7c10f
    Size: 1.28 MB
  2. cups-client-1.6.3-52.0.3.el7.AXS7.x86_64.rpm
    MD5: cd767c070479a7ac7172e9569ebf0bd9
    SHA-256: 7cfc787e156e55b57877721edb5fbd36a8d84ab060ab4cc300cdd0695248a564
    Size: 152.73 kB
  3. cups-devel-1.6.3-52.0.3.el7.AXS7.i686.rpm
    MD5: 6144e7cc9789f2b696a95a564a5a8294
    SHA-256: ad21a492202830d1149c2f66a5bac3283a7d4991aebc3e5d071e46153cbb99a4
    Size: 133.84 kB
  4. cups-devel-1.6.3-52.0.3.el7.AXS7.x86_64.rpm
    MD5: d307730eba314523d45a21e7f51689ab
    SHA-256: 3a70072ec76616acc688505d1dcf202fadffd1656810cd1348f69f5d3f525dab
    Size: 133.83 kB
  5. cups-filesystem-1.6.3-52.0.3.el7.AXS7.noarch.rpm
    MD5: 23cab8a4b9b6f97d571784bbf9c874a4
    SHA-256: 622594098b28d5ce7bbc3a9ee8f4eeaf37637e5be8ff145bab3e980909ff903d
    Size: 97.80 kB
  6. cups-libs-1.6.3-52.0.3.el7.AXS7.i686.rpm
    MD5: eca78c581c7953e01a16799985fdf301
    SHA-256: d4be768657e75c695614e9b8e68d37d11a5015b023eed940df2a2449721fb348
    Size: 360.83 kB
  7. cups-libs-1.6.3-52.0.3.el7.AXS7.x86_64.rpm
    MD5: 252e32d52a1938cbe2f4f8fef4535c1e
    SHA-256: 6bb73b3f920272f72cd86d15d6cfde0dc6011f29ab719987c1fff9e04614e44f
    Size: 358.93 kB
  8. cups-lpd-1.6.3-52.0.3.el7.AXS7.x86_64.rpm
    MD5: 5f5b22a0845904cba5761314537b5726
    SHA-256: ea0f15da1e9f010c8c11ddd6fd9efbaacdccc6a0d52de5c1119ce12e5360b177
    Size: 108.94 kB