[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3826-1] cups security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3826-1                [email protected]
https://www.debian.org/lts/security/                    Thorsten Alteholz
June 13, 2024                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : cups
Version        : 2.2.10-6+deb10u10
CVE ID         : CVE-2024-35235


An issue has been found in cups, the Common UNIX Printing System(tm).
When starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.


For Debian 10 buster, this problem has been fixed in version
2.2.10-6+deb10u10.

We recommend that you upgrade your cups packages.

For the detailed security status of cups please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/cups

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmZra0BfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEeN9hAAul6QL5Sm9z30vnnT2ZnAPcBg0N8CyRPNYt5klYPrZfaLMz0LB7NqyATL
boSyySCbJF3+WL8uLuwXre9rZ2tIKtXXFfbHvNoOamg9BpmHvod2jYvu9SwE9sBe
NBiB4v8/EJARRsFxmbYoBY5Pci1iNswfAYQHdEcbLWWeHzLORVY2TmBWhhEcoiPJ
GiNo3H+G9YaA6lD+HR84lkzv/el6D3LYISdp+5PpUyVViGctVDUl9zNMAKdZrbt+
FZc4KC3Q8LzHTQo6wuFNpvnw486Dpsi1QrsZ8gLHd+9W+AsATFuCgQsqY3NWf1iI
okDnJl4mIbrLjiBVX6JeYEC8waUMorVJLCCjB7BzYenwMuqAbK4y7N/C2MciKoBP
gH8R8vLKDRaLCs5K4ucT7Sy4IhNcwOGB+M3HQ0qgLs9Lj7mDbRo3vNT+3zRYC+Vq
cDX7MwDJRxAqUyfdc5OTGOPKhcLIvJYgq90w4tIi/7CzUl83yYyRA70PFcVqTuWB
mPAGPXU37pP8nXimAE81dw+fk/NUeJc5lros9b36T23tAoba0EezcEAbKhJdMpB4
/IBwc27uLlfWes600pYTmgIYVEwbvwzamzwVaOEw9HVc8OxZwqcZE4D2B9rozYmg
5nTRd/5cHSs1EVRwZz/Xwppx+aInbLL1igtnfCuvqAMXmQ2EokY=
=8RnW
-----END PGP SIGNATURE-----


Reply to: