USN-6844-2: CUPS regression
USN-6844-1 fixed vulnerabilities in the CUPS package. The update lead to the discovery of a regression in CUPS with regards to how the cupsd daemon handles Listen configuration directive. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Rory McNamara discovered that when starting the cupsd server with a Listen configuration item, the cupsd process fails to validate if bind call passed. An attacker could possibly trick cupsd to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6844-2?
USN-6844-2 addresses a regression issue in the CUPS package that impacts the cupsd daemon's handling of the Listen configuration directive.
How do I fix USN-6844-2?
To resolve the issues relating to USN-6844-2, update the CUPS package to the recommended versions provided in the advisory.
What versions of CUPS are affected by USN-6844-2?
USN-6844-2 affects multiple versions of the CUPS package across Ubuntu 16.04, 18.04, 20.04, 22.04, 23.10, and 24.04.
Is there a risk of service disruption with USN-6844-2?
Updating to the fixed version in USN-6844-2 is necessary to prevent potential security risks and ensure continued functionality of the printing service.
What is the primary issue addressed in USN-6844-2?
USN-6844-2 fixes a regression introduced in a previous update, affecting how the CUPS daemon processes configuration directives.