CVE-2024-35235
published 2024-06-11CVE-2024-35235: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd…
PriorityP340medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
2.42%
82.3th percentile
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.3op2-3+deb11u7 | 2.3.3op2-3+deb11u7 |
| apple | cups | >= 0 < 2.4.2-3+deb12u6 | 2.4.2-3+deb12u6 |
| apple | cups | >= 0 < 2.4.7-2 | 2.4.7-2 |
| apple | cups | >= 0 < 2.4.7-2 | 2.4.7-2 |
| debian | cups | < cups 2.4.2-3+deb12u6 (bookworm) | cups 2.4.2-3+deb12u6 (bookworm) |
| debian | debian_linux | — | — |
| msrc | azl3_cups_2.3.3op2-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_cups_2.4.10-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cups_2.3.3op2-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openprinting | cups | <= 2.4.8 | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2024-06-24
CVE-2024-35235 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to arbitrary chmod paths with specially
crafted configuration file.
Rory McNamara discovered that when starting the cupsd server with a
Listen configuration item, the cupsd process fails to validate if
bind call passed. An attacker could possibly trick cupsd to perform
an arbitrary chmod of the provided argument, providing world-writable
access to the target.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Cupsd Listen arbitrary chmod 0140777
vendor_msrc·2024-06-11·CVSS 4.4
CVE-2024-35235 [MEDIUM] CWE-59 Cupsd Listen arbitrary chmod 0140777
Cupsd Listen arbitrary chmod 0140777
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.co
Red Hat
cups: Cupsd Listen arbitrary chmod 0140777
vendor_redhat·2024-06-11·CVSS 4.4
CVE-2024-35235 [MEDIUM] CWE-277 cups: Cupsd Listen arbitrary chmod 0140777
cups: Cupsd Listen arbitrary chmod 0140777
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full contro
Debian
CVE-2024-35235: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
vendor_debian·2024·CVSS 4.4
CVE-2024-35235 [MEDIUM] CVE-2024-35235: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf co
OSV
CVE-2024-35235: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
osv·2024-06-11·CVSS 6.7
CVE-2024-35235 [MEDIUM] CVE-2024-35235: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/06/11/1http://www.openwall.com/lists/oss-security/2024/06/12/4http://www.openwall.com/lists/oss-security/2024/06/12/5https://git.launchpad.net/ubuntu/+source/apparmor/tree/profiles/apparmor.d/abstractions/user-tmp#n21https://github.com/OpenPrinting/cups/blob/aba917003c8de55e5bf85010f0ecf1f1ddd1408e/cups/http-addr.c#L229-L240https://github.com/OpenPrinting/cups/commit/ff1f8a623e090dee8a8aadf12a6a4b25efac143dhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-vvwp-mv6j-hw6fhttps://lists.debian.org/debian-lts-announce/2024/06/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2024/06/11/1http://www.openwall.com/lists/oss-security/2024/06/12/4http://www.openwall.com/lists/oss-security/2024/06/12/5http://www.openwall.com/lists/oss-security/2024/11/08/3https://git.launchpad.net/ubuntu/+source/apparmor/tree/profiles/apparmor.d/abstractions/user-tmp#n21https://github.com/OpenPrinting/cups/blob/aba917003c8de55e5bf85010f0ecf1f1ddd1408e/cups/http-addr.c#L229-L240https://github.com/OpenPrinting/cups/commit/ff1f8a623e090dee8a8aadf12a6a4b25efac143dhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-vvwp-mv6j-hw6fhttps://lists.debian.org/debian-lts-announce/2024/06/msg00001.html
2024-06-11
Published