https://seclists.org/oss-sec/2024/q2/282: CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777
Published Jun 12, 2024
·Updated
Affected Software
1 affected component
OpenPrinting CUPS
Frequently Asked Questions
1
What is the severity of CVE-2024-35235?
CVE-2024-35235 is classified as a critical vulnerability due to its potential for arbitrary file permission changes when exploiting cupsd running as root.
2
How do I fix CVE-2024-35235?
To mitigate CVE-2024-35235, update OpenPrinting CUPS to the latest version where the vulnerability has been patched.
3
What systems are affected by CVE-2024-35235?
CVE-2024-35235 affects systems running OpenPrinting CUPS that use cupsd as a print server.
4
What are the risks of CVE-2024-35235?
Exploitation of CVE-2024-35235 can allow an attacker to change file permissions, making sensitive files world writable.
5
When was CVE-2024-35235 published?
CVE-2024-35235 was published on June 12, 2024.