REDHAT-BUG-2416039: Medium severity OpenPrinting CUPS vulnerability
A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2416039?
The severity of REDHAT-BUG-2416039 is critical due to the potential for an out-of-bounds write that could be exploited.
How do I fix REDHAT-BUG-2416039?
To fix REDHAT-BUG-2416039, you should update CUPS to the latest version provided in the security advisories from Red Hat.
Who is affected by REDHAT-BUG-2416039?
Users with permissions defined by the SystemGroup directive in /etc/cups/cups-files.conf are affected by REDHAT-BUG-2416039.
What causes the vulnerability REDHAT-BUG-2416039?
REDHAT-BUG-2416039 is caused by the ability of a user to inject malicious configuration lines through the CUPS web UI.
What impact does REDHAT-BUG-2416039 have on my system?
The impact of REDHAT-BUG-2416039 can lead to unauthorized access and potential system compromise due to out-of-bounds writes.