Bug 32281 - cups new security issue CVE-2023-32360 and CVE-2023-4504
Summary: cups new security issue CVE-2023-32360 and CVE-2023-4504
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO MGA8-64-OK MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-09-13 14:05 CEST by Nicolas Salguero
Modified: 2023-10-10 19:23 CEST (History)
7 users (show)

See Also:
Source RPM: cups-2.4.6-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2023-09-13 14:05:25 CEST
Ubuntu has issued an advisory on September 12:
https://ubuntu.com/security/notices/USN-6361-1

The commit that fixed the issue is:
https://github.com/OpenPrinting/cups/commit/a0c8b9c9556882f00c68b9727a95a1b6d1452913
Nicolas Salguero 2023-09-13 14:05:49 CEST

CC: (none) => nicolas.salguero
Source RPM: (none) => cups-2.3.3op2-1.3.mga8.src.rpm

Comment 1 Lewis Smith 2023-09-13 19:35:27 CEST
Normally done by tv, other packagers are now committing it; so assigning globally, CC'ing Thierry. Note the M8; M9 is at v2.4.6.

Assignee: bugsquad => pkg-bugs
CC: (none) => thierry.vignaud

Comment 2 Nicolas Salguero 2023-09-14 15:32:40 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

It was discovered that CUPS incorrectly authenticated certain remote requests. A remote attacker could possibly use this issue to obtain recently printed documents. (CVE-2023-32360)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32360
https://ubuntu.com/security/notices/USN-6361-1
========================

Updated packages in core/updates_testing:
========================
cups-2.3.3op2-1.4.mga8
cups-common-2.3.3op2-1.4.mga8
cups-filesystem-2.3.3op2-1.4.mga8
cups-printerapp-2.3.3op2-1.4.mga8
lib(64)cups2-2.3.3op2-1.4.mga8
lib(64)cups2-devel-2.3.3op2-1.4.mga8

from SRPM:
cups-2.3.3op2-1.4.mga8.src.rpm

Assignee: pkg-bugs => nicolas.salguero
Status: NEW => ASSIGNED

Nicolas Salguero 2023-09-18 09:23:14 CEST

Assignee: nicolas.salguero => qa-bugs

Comment 3 Herman Viaene 2023-09-21 11:43:47 CEST
MGA8-64 Xfce on Acer Aspire
No installation issues
Reomved wifi HP Envy 6022 printer in MCC and added it again, and printed test page, all OK.

CC: (none) => herman.viaene

Comment 4 Nicolas Salguero 2023-09-25 10:51:34 CEST
Ubuntu has issued an advisory for CVE-2023-4504 on September 20:
https://ubuntu.com/security/notices/USN-6391-1

The issue is fixed by: https://github.com/OpenPrinting/cups/commit/2431caddb7e6a87f04ac90b5c6366ad268b6ff31

Mageia 8 and 9 are also affected.

Whiteboard: (none) => MGA9TOO, MGA8TOO
Assignee: qa-bugs => pkg-bugs
Status: ASSIGNED => NEW
Version: 8 => Cauldron
Status comment: (none) => Fi
Summary: cups new security issue CVE-2023-32360 => cups new security issue CVE-2023-32360 and CVE-2023-4504

Nicolas Salguero 2023-09-25 10:51:49 CEST

Status comment: Fi => Fixed upstream in 2.4.7

Comment 5 Nicolas Salguero 2023-09-26 10:05:00 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

It was discovered that CUPS incorrectly authenticated certain remote requests. A remote attacker could possibly use this issue to obtain recently printed documents. (CVE-2023-32360)

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. (CVE-2023-4504)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32360
https://ubuntu.com/security/notices/USN-6361-1
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4504
https://ubuntu.com/security/notices/USN-6391-1
========================

Updated packages in 9/core/updates_testing:
========================
cups-2.4.6-1.1.mga9
cups-common-2.4.6-1.1.mga9
cups-filesystem-2.4.6-1.1.mga9
cups-printerapp-2.4.6-1.1.mga9
lib(64)cups2-2.4.6-1.1.mga9
lib(64)cups2-devel-2.4.6-1.1.mga9

from SRPM:
cups-2.4.6-1.1.mga9.src.rpm

Updated packages in 8/core/updates_testing:
========================
cups-2.3.3op2-1.5.mga8
cups-common-2.3.3op2-1.5.mga8
cups-filesystem-2.3.3op2-1.5.mga8
cups-printerapp-2.3.3op2-1.5.mga8
lib(64)cups2-2.3.3op2-1.5.mga8
lib(64)cups2-devel-2.3.3op2-1.5.mga8

from SRPM:
cups-2.3.3op2-1.5.mga8.src.rpm

Source RPM: cups-2.3.3op2-1.3.mga8.src.rpm => cups-2.4.6-1.mga9.src.rpm
Status comment: Fixed upstream in 2.4.7 => (none)
Whiteboard: MGA9TOO, MGA8TOO => MGA8TOO
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 9

Comment 6 Morgan Leijström 2023-09-27 00:07:10 CEST
mga9-64 OK here, printing to an Ethernet printer, and to Boomaga.

CC: (none) => fri

Comment 7 Herman Viaene 2023-10-09 16:43:06 CEST
MGA8-64 Xfce on Acer Aspire
No installation issues
Removed wifi HP Envy 6022 printer in MCC and added it again, all OK.
Comment 8 Thomas Andrews 2023-10-10 04:03:25 CEST
MGA9-64 Plasma, no installation issues. Printed a photo to a usb Color Laserjet CP1215 in monochrome. This printer uses the FOO2HP driver, rather than hplip.

Worked OK, giving it a MGA9 OK, based on this test and comment 6.

Whiteboard: MGA8TOO => MGA8TOO MGA9-64-OK
CC: (none) => andrewsfarm

Comment 9 Thomas Andrews 2023-10-10 04:50:47 CEST
MGA8-Plasma, AMD Phenom II X4, Radeon HD 8490 graphics.

Used qarepo to get the package candidates, then went to MCC and installed system-config-printer and dependencies, including cups. Added the Color Laserjet CP1215, and printed a test page. No issues to report.

Giving this a MGA8 OK based on this test and comment 7. 

Validating. Advisory in comment 5.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: MGA8TOO MGA9-64-OK => MGA8TOO MGA8-64-OK MGA9-64-OK

Comment 10 Marja Van Waes 2023-10-10 11:41:53 CEST
The advisory from comment 5 has been added

CC: (none) => marja11
Keywords: (none) => advisory

Comment 11 Mageia Robot 2023-10-10 19:23:18 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0284.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.