https://seclists.org/oss-sec/2024/q4/71: CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777
Published Nov 8, 2024
·Updated
Affected Software
1 affected component
OpenPrinting CUPS
Frequently Asked Questions
1
What is the severity of CVE-2024-35235?
CVE-2024-35235 is considered critical due to the potential for arbitrary chmod manipulations by an attacker.
2
How do I fix CVE-2024-35235?
To mitigate CVE-2024-35235, update to the latest version of OpenPrinting CUPS which addresses the vulnerability.
3
What are the potential impacts of CVE-2024-35235?
The vulnerability allows the cupsd service running as root to change file permissions, potentially making sensitive files world writable.
4
Who is affected by CVE-2024-35235?
Any system running OpenPrinting CUPS with the vulnerable settings can be affected by CVE-2024-35235.
5
When was CVE-2024-35235 published?
CVE-2024-35235 was published on November 8, 2024.