cups: CVE-2022-26691: authorization bypass when using "local" authorization

Related Vulnerabilities: CVE-2022-26691  

Debian Bug report logs - #1011769
cups: CVE-2022-26691: authorization bypass when using "local" authorization

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Thu, 26 May 2022 13:39:20 UTC

Severity: grave

Tags: security, upstream

Found in versions cups/2.4.1op1-2, cups/2.2.10-6, cups/2.3.3op2-3+deb11u1, cups/2.3.3op2-3, cups/2.2.10-6+deb10u5

Fixed in versions cups/2.3.3op2-3+deb11u2, cups/2.2.10-6+deb10u6, cups/2.4.2-1

Done: Thorsten Alteholz <debian@alteholz.de>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Printing Team <debian-printing@lists.debian.org>:
Bug#1011769; Package src:cups. (Thu, 26 May 2022 13:39:21 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Printing Team <debian-printing@lists.debian.org>. (Thu, 26 May 2022 13:39:22 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: cups: CVE-2022-26691: authorization bypass when using "local" authorization
Date: Thu, 26 May 2022 15:36:38 +0200
Source: cups
Version: 2.4.1op1-2
Severity: grave
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Control: found -1 2.3.3op2-3+deb11u1
Control: found -1 2.3.3op2-3
Control: found -1 2.2.10-6+deb10u5
Control: found -1 2.2.10-6
Control: fixed -1 2.3.3op2-3+deb11u2
Control: fixed -1 2.2.10-6+deb10u6

Hi,

The following vulnerability was published for cups.

Thorsten, just filling for tracking in BTS.

CVE-2022-26691[0]:
| authorization bypass when using "local" authorization

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-26691
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26691

Regards,
Salvatore



Marked as found in versions cups/2.3.3op2-3+deb11u1. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:22 GMT) (full text, mbox, link).


Marked as found in versions cups/2.3.3op2-3. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:22 GMT) (full text, mbox, link).


Marked as found in versions cups/2.2.10-6+deb10u5. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:23 GMT) (full text, mbox, link).


Marked as found in versions cups/2.2.10-6. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:23 GMT) (full text, mbox, link).


Marked as fixed in versions cups/2.3.3op2-3+deb11u2. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:24 GMT) (full text, mbox, link).


Marked as fixed in versions cups/2.2.10-6+deb10u6. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 26 May 2022 13:39:25 GMT) (full text, mbox, link).


Reply sent to Thorsten Alteholz <debian@alteholz.de>:
You have taken responsibility. (Fri, 27 May 2022 00:33:03 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Fri, 27 May 2022 00:33:03 GMT) (full text, mbox, link).


Message #22 received at 1011769-done@bugs.debian.org (full text, mbox, reply):

From: Thorsten Alteholz <debian@alteholz.de>
To: 1011769-done@bugs.debian.org
Subject: Bug#1011769: fixed in cups 2.4.2-1
Date: Thu, 26 May 2022 23:32:06 +0000 (UTC)
Source: cups
Source-Version: 2.4.2-1
Done: Thorsten Alteholz <debian@alteholz.de>

Manually closing this bug as the fix for this CVE was done in version 
2.4.2-1.

  Thorsten




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri May 27 13:12:40 2022; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.