USN-6844-1: CUPS vulnerability
Rory McNamara discovered that when starting the cupsd server with a Listen configuration item, the cupsd process fails to validate if bind call passed. An attacker could possibly trick cupsd to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6844-1?
The vulnerability identified by USN-6844-1 is classified as a high severity issue due to potential arbitrary chmod execution.
How do I fix USN-6844-1?
To resolve the USN-6844-1 vulnerability, update the CUPS package to the appropriate remedial version for your Ubuntu release.
What versions of Ubuntu are affected by USN-6844-1?
USN-6844-1 affects multiple Ubuntu versions, including 16.04, 18.04, 20.04, 22.04, 23.10, and 24.04.
What is CUPS and why is USN-6844-1 significant?
CUPS, or Common Unix Printing System, is a printing system used by Ubuntu that is significant due to its role in managing print jobs and potential security vulnerabilities.
How can I verify if my CUPS package is vulnerable to USN-6844-1?
You can check your CUPS package version against the versions listed in the USN-6844-1 advisory to determine if it is vulnerable.