https://seclists.org/oss-sec/2024/q2/281: CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777
Published Jun 12, 2024
·Updated
Affected Software
1 affected component
OpenPrinting CUPS
Frequently Asked Questions
1
What is the severity of CVE-2024-35235?
CVE-2024-35235 is classified as a critical vulnerability due to its potential to allow arbitrary changes in file permissions by exploiting cupsd running with root privileges.
2
How do I fix CVE-2024-35235?
To mitigate CVE-2024-35235, upgrade to the latest version of OpenPrinting CUPS that addresses this vulnerability.
3
What systems are affected by CVE-2024-35235?
CVE-2024-35235 affects OpenPrinting CUPS installations that run cupsd with root permissions.
4
What is the impact of CVE-2024-35235?
The impact of CVE-2024-35235 is the potential to change permissions of user or system files to be world writable, which can lead to unauthorized access.
5
When was CVE-2024-35235 published?
CVE-2024-35235 was published on June 12, 2024.