June 25, 2024, 5:48 p.m. |

Packet Storm packetstormsecurity.com

Ubuntu Security Notice 6844-1 - Rory McNamara discovered that when starting the cupsd server with a Listen configuration item, the cupsd process fails to validate if bind call passed. An attacker could possibly trick cupsd to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.

access argument attacker bind call configuration notice process security security notice server target trick ubuntu usn world

Senior Analyst, Corporate Security

@ Toast | Bengaluru, Karnataka, India

Senior Product Manager

@ Microsoft | Bengaluru, Karnataka, India

VP, Product Marketing

@ Proofpoint | Sunnyvale, CA

Senior Sales Engineer - NYC

@ Juniper Networks | New York City, United States

Sr. Analyst | Onsite, Bangalore.

@ Optiv | Bengaluru

Senior Data Analyst (ArcSight)

@ Capgemini | Washington, DC, District of Columbia, United States