CVE-2023-34241: CUPS vulnerable to use-after-free in cupsdAcceptClient()
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
AMD. A race condition was addressed with improved state handling.
— Apple
Apple CUPS is vulnerable to a denial of service, caused by a use-after-free in cupsdAcceptClient(). By reading the log, a local attacker could exploit this vulnerability to exfiltrate private keys and info from a privileged cups daemon or cause the application to crash.
— IBM
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppSandbox. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.2.7-1ubuntu2.10+ - Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.1.3-4ubuntu0.11+ - Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.3.1-9ubuntu1.4 - Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.4.1 - Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.4.2-1ubuntu2.2 - Upgrade
Upgrade
ubuntu/cupsto a version that resolves this vulnerability.Fixed in 2.4.2-3ubuntu2.2 - Upgrade
Upgrade
debian/cupsto a version that resolves this vulnerability.Fixed in 2.2.10-6+deb10u9Fixed in 2.3.3op2-3+deb11u6Fixed in 2.4.2-3+deb12u5Fixed in 2.4.7-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.7.9 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.6.8 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2 - Upgrade
Upgrade
OpenPrinting CUPSto a version that resolves this vulnerability.Fixed in 2.4.6 - Configuration
In cupsd.conf, avoid the scenario where HostNameLookups Double is set and the IP Address double-lookup fails (the described use-after-free occurs when LogLevel is warn or higher and HostNameLookups Double is set).
OpenPrinting CUPS HostNameLookups Double (cupsd.conf) = unset/disable (set to not Double) - Configuration
If CUPS is compiled with TCP wrappers, adjust /etc/hosts.allow and /etc/hosts.deny so connections are not refused by these rules (the described use-after-free occurs when LogLevel is warn or higher and the connection is refused by TCP wrapper rules).
OpenPrinting CUPS (TCP wrappers) /etc/hosts.allow and /etc/hosts.deny rules (connection refused) = permit the connections instead of refusing them via rules - Configuration
Set LogLevel to a value lower than warn (the described use-after-free in cupsdAcceptClient happens when LogLevel is warn or higher).
OpenPrinting CUPS LogLevel = below warn
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40442
- CVE-2023-34425
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-41990
- CVE-2023-36854
- CVE-2023-32418
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38603
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-37285
- CVE-2023-38604
- CVE-2023-38606
- CVE-2023-32441
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-38571
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38259
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32422
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-32416
- CVE-2023-36495
- CVE-2023-40440
- CVE-2023-38421
- CVE-2023-38258
- CVE-2023-1916
- CVE-2023-32442
- CVE-2023-38605
- CVE-2023-40439
- CVE-2023-38616
- CVE-2023-38580
- CVE-2023-36862
- CVE-2023-42828
- CVE-2023-40437
- CVE-2022-3970
- CVE-2023-28200
- CVE-2023-32734
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38410
- CVE-2023-38609
- CVE-2023-38564
- CVE-2023-32654
- CVE-2023-38608
- CVE-2023-40397
- CVE-2023-38572
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-43000
Frequently Asked Questions
What is CVE-2023-34241?
CVE-2023-34241 is a logic issue in OpenPrinting CUPS that has been addressed with improved state management.
What is the severity of CVE-2023-34241?
The severity of CVE-2023-34241 is high with a CVSS Score of 7.1.
How does CVE-2023-34241 affect OpenPrinting CUPS?
CVE-2023-34241 affects OpenPrinting CUPS versions earlier than 2.4.6.
How can I fix CVE-2023-34241 in OpenPrinting CUPS?
To fix CVE-2023-34241 in OpenPrinting CUPS, update to version 2.4.6 or later.
Are there any official references for CVE-2023-34241?
Yes, you can find official references for CVE-2023-34241 at the following links: - [GitHub Commit](https://github.com/OpenPrinting/cups/commit/9809947a959e18409dcf562a3466ef246cb90cb2) - [GitHub Release](https://github.com/OpenPrinting/cups/releases/tag/v2.4.6) - [OpenPrinting CUPS Security Advisory](https://github.com/OpenPrinting/cups/security/advisories/GHSA-qjgh-5hcq-5f25)