OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opengroup
Opengroup unix |
|
| CPEs | cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Opengroup
Opengroup unix |
Wed, 03 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1173 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openprinting
Openprinting cups |
|
| Vendors & Products |
Openprinting
Openprinting cups |
Sat, 29 Nov 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 29 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15. | |
| Title | OpenPrinting CUPS vulnerable to stack based out-of-bound write | |
| Weaknesses | CWE-124 CWE-129 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-29T02:15:39.913Z
Updated: 2025-12-03T15:52:35.319Z
Reserved: 2025-10-03T22:21:59.614Z
Link: CVE-2025-61915
Updated: 2025-11-29T02:34:46.323Z
Status : Analyzed
Published: 2025-11-29T03:15:59.520
Modified: 2025-12-04T17:15:19.827
Link: CVE-2025-61915