-
Notifications
You must be signed in to change notification settings - Fork 694
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
There are several CVEs targeting the CUPS software, some of them for various subpackages such as cups-browsed, or libppd. These subpackages often borrow lots of code from the mainline CUPS package, causing CVEs to be theoretically applicable in both places. These CVEs can be combined and exploited for remote command execution as described in https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ These CVEs for CUPS and various CUPS related packages include: - CVE-2024-47176 - CVE-2024-47076 - CVE-2024-47175 - CVE-2024-47177 While Photon is *NOT* at risk of this particular exploit chain, because we don't have the cups-browsed service, CVEs such as CVE-2024-47175 which applies to libppd also affects the same code in mainline CUPS and should be patched. There are 5 commits needed to remediate this exploit in mainline CUPS, as described in https://www.openwall.com/lists/oss-security/2024/09/27/3 Update to the latest subversion 2.4.11 in order to consume these fixes. Change-Id: Ieff8b832dfeb1004c1dcd3b7dd93b0c834a88ffd Reviewed-on: http://photon-gerrit.lvn.broadcom.net/c/photon/+/24932 Reviewed-by: Harinadh Dommaraju <harinadh.dommaraju@broadcom.com> Reviewed-by: Shreenidhi Shedi <shreenidhi.shedi@broadcom.com> Tested-by: gerrit-photon <svc.photon-ci@broadcom.com>
- Loading branch information
1 parent
af3c100
commit d007e98
Showing
4 changed files
with
15 additions
and
7 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters