CVE-2024-35235: Cupsd Listen arbitrary chmod 0140777

Published Jun 4, 2024
·
Updated

Cupsd Listen arbitrary chmod 0140777

Other sources

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a FoomaticRIPCommandLine argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.

NVD

When starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.

When setting up the bind for unix sockets configured in the Listen parameters of the configuration file, the code does not check for a successful call to unlink and bind prior to performing the call to chmod. A sufficiently fast attacker could place a symbolic link at the configured location after the call to unlink, causing the bind to fail once again and performing a successful chmod.

Red Hat

Affected Software

7 affected componentsFixes available
debian/cups<=2.3.3op2-3+deb11u2
2.3.3op2-3+deb11u82.4.2-3+deb12u72.4.10-1
redhat/CUPS<2.4.9
2.4.9
OpenPrinting CUPS<=2.4.8
Debian Debian Linux=10.0
Microsoft azl3 cups 2.4.10-1
Microsoft azl3 cups 2.3.3op2-6
Microsoft cbl2 cups 2.3.3op2-9

Event History

Jun 11, 2024
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyAffected Software
Jun 29, 2024
Data Sourced
via Launchpad·02:45 PM
Description
Sep 11, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Sep 13, 2024
Data Sourced
via Ubuntu·02:57 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-35235?

CVE-2024-35235 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2024-35235?

To fix CVE-2024-35235, upgrade to CUPS version 2.4.9 or later for Red Hat, or to specific Debian versions: 2.3.3op2-3+deb11u8, 2.4.2-3+deb12u7, or 2.4.10-1.

3

What systems are affected by CVE-2024-35235?

CVE-2024-35235 affects CUPS versions 2.4.8 and earlier on Linux and other Unix-like operating systems.

4

What is the impact of CVE-2024-35235?

The impact of CVE-2024-35235 could potentially allow an attacker to manipulate the cupsd process through a symbolic link.

5

When was CVE-2024-35235 disclosed?

CVE-2024-35235 was disclosed on June 11, 2024.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203