Bug 32040 - cups new security issue CVE-2023-34241
Summary: cups new security issue CVE-2023-34241
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-06-22 20:37 CEST by David Walser
Modified: 2023-07-07 07:56 CEST (History)
7 users (show)

See Also:
Source RPM: cups-2.3.3op2-1.2.mga8.src.rpm
CVE: CVE-2023-34241
Status comment:


Attachments

Description David Walser 2023-06-22 20:37:37 CEST
A security issue fixed upstream in CUPS has been announced today (June 22):
https://www.openwall.com/lists/oss-security/2023/06/22/4

The commit that fixed the issue is linked in the message above.

We should probably also update Cauldron to the latest upstream, due to bug and regression fixes:
https://openprinting.github.io/cups-2.4.3/
https://openprinting.github.io/cups-2.4.4/
https://openprinting.github.io/cups-2.4.5/
https://openprinting.github.io/cups-2.4.6/

CUPS 2.4.6 also contains the fix for this security issue.

Mageia 8 is also affected.
David Walser 2023-06-22 20:37:53 CEST

Status comment: (none) => Fixed upstream in 2.4.6
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2023-06-22 20:51:17 CEST
A big version jump.
Cups is normally done by Thierry, so assigning this to you.
CC'ing NicolasS who did a recent patch.

CC: (none) => nicolas.salguero
Assignee: bugsquad => thierry.vignaud

Comment 2 David Walser 2023-06-22 21:01:10 CEST
Ubuntu has issued an advisory for this today (June 22):
https://ubuntu.com/security/notices/USN-6184-1
Comment 3 Nicolas Lécureuil 2023-06-27 01:23:55 CEST
fixed in cauldron

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
CC: (none) => mageia

Comment 4 Nicolas Salguero 2023-06-27 15:22:40 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use-after-free in cupsdAcceptClient(). (CVE-2023-34241)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34241
https://www.openwall.com/lists/oss-security/2023/06/22/4
https://ubuntu.com/security/notices/USN-6184-1
========================

Updated packages in core/updates_testing:
========================
cups-2.3.3op2-1.3.mga8
cups-common-2.3.3op2-1.3.mga8
cups-filesystem-2.3.3op2-1.3.mga8
cups-printerapp-2.3.3op2-1.3.mga8
lib(64)cups2-2.3.3op2-1.3.mga8
lib(64)cups2-devel-2.3.3op2-1.3.mga8

from SRPM:
cups-2.3.3op2-1.3.mga8.src.rpm

Assignee: thierry.vignaud => qa-bugs
Status comment: Fixed upstream in 2.4.6 => (none)
CVE: (none) => CVE-2023-34241
Source RPM: cups-2.4.2-4.mga9.src.rpm => cups-2.3.3op2-1.2.mga8.src.rpm
Status: NEW => ASSIGNED

Comment 5 Thomas Andrews 2023-06-28 20:06:51 CEST
No installation issues. Tried printing with each of my HP printers:

Deskjet 5650 - uses the hplip driver, test pages printed as they should.

Color Laserjet CP1215 - uses the foo2hp driver, test pages printed as they should.

Envy Photo 7858 - wireless connection, uses hplip, went through the motions of printing, but the cartridges are dried up. Scanner function works as it should.

So it looks OK here with my HP printers, anyway. It probably should be checked with printers of another brand or two before validating.

CC: (none) => andrewsfarm

Comment 6 Herman Viaene 2023-06-29 17:09:32 CEST
Print and scan with wireless HP Envy 6022, works OK.

CC: (none) => herman.viaene

Comment 7 Len Lawrence 2023-06-29 22:52:15 CEST
mga8, x64
HP Photosmart 5520 wireless; print and scan OK.

CC: (none) => tarazed25

Comment 8 Thomas Andrews 2023-07-02 15:42:15 CEST
Printed a pdf of an image from Gwenview to my desktop using cups-pdf, so we have at least one test with a non-HP printer, even if it is a virtual printer. No issues, so I'm giving this an OK.

Validating. Advisory in comment 4.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK

Dave Hodgins 2023-07-06 23:08:33 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 9 Mageia Robot 2023-07-07 07:56:38 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0223.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.