Description Preview
The vulnerability in OpenPrinting CUPS versions 2.4.8 and earlier involves the cupsd server being tricked into performing an arbitrary chmod operation when started with a Listen configuration item pointing to a symbolic link. This manipulation can result in granting world-writable access to the target, potentially allowing unauthorized modification of user or system files. As the cupsd process often runs with root privileges, this vulnerability can lead to significant security risks, including the potential for executing arbitrary commands with elevated privileges.
Overview
- CVE ID: CVE-2024-35235
- CVSS Base Score: 4.4 (Medium)
- CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CWE IDs: CWE-59, CWE-252
- Vendor: OpenPrinting
- Product: CUPS
- Affected Versions: <= 2.4.8
- Attack Vector: Local
- Privileges Required: High
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
Remediation
To remediate this vulnerability, users of OpenPrinting CUPS should update to a version beyond 2.4.8 where the issue has been patched. Specifically, applying commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains the fix for this vulnerability. It is crucial to ensure that the cupsd server is not started with a Listen configuration item pointing to a symbolic link to prevent unauthorized chmod operations.
References
- Advisory: OpenPrinting CUPS Security Advisory
- Patch Commit: GitHub Commit
- AppArmor Configuration: Ubuntu AppArmor Configuration
- Source Code Reference: CUPS Source Code
- Additional Information:
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Health Care & Social AssistanceHealth Care & Social Assistance
- Public AdministrationPublic Administration
- Finance and InsuranceFinance and Insurance
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Educational ServicesEducational Services
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Other Services (except Public Administration)Other Services (except Public Administration)
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- InformationInformation
- ConstructionConstruction
- Wholesale TradeWholesale Trade
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing