OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cups | Ubuntu | esm-infra/bionic | * |
| Cups | Ubuntu | esm-infra/focal | * |
| Cups | Ubuntu | esm-infra/xenial | * |
| Cups | Ubuntu | jammy | * |
| Cups | Ubuntu | noble | * |
| Cups | Ubuntu | plucky | * |
| Cups | Ubuntu | questing | * |
| Cups | Ubuntu | upstream | * |