安全公告详情

NS-SA-2025-0113

2025-07-25 16:49:52

简介

moderate: cups/binutils security update

严重级别

moderate

主题

An update for cups/binutils is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

cups:
binutils:


Security Fix(es):
cups: A flaw was found in the cupsd server. When starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Since cupsd is often running as root, this issue can result in the change of permission of any user or system files to be world writable.(CVE-2024-35235)
cups: A vulnerability was found in CUPS and libppd, where a failure to validate the length provided in an attacker-crafted PPD PostScript document can lead to a heap-based buffer overflow, causing a denial of service or, in some cases, execute arbitrary code, depending on how the application processes untrusted PPD files.(CVE-2023-4504)
cups: bugfix
binutils: A flaw was found in GNU Binutils. This vulnerability allows a stack-based buffer overflow via manipulation of the buf argument in the disassemble_bytes function.(CVE-2025-0840)
binutils: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • cups
  • binutils

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["cups-filesystem-2.4.10-1.zncgsl7.1.noarch.rpm","cups-libs-2.4.10-1.zncgsl7.1.x86_64.rpm","cups-ipptool-2.4.10-1.zncgsl7.1.x86_64.rpm","cups-client-2.4.10-1.zncgsl7.1.x86_64.rpm","cups-2.4.10-1.zncgsl7.1.x86_64.rpm","cups-devel-2.4.10-1.zncgsl7.1.x86_64.rpm"],"source":"cups-2.4.10-1.zncgsl7.1.src.rpm"},{"binary":["binutils-gold-2.41-2.zncgsl7.6.x86_64.rpm","binutils-2.41-2.zncgsl7.6.x86_64.rpm","binutils-devel-2.41-2.zncgsl7.6.x86_64.rpm"],"source":"binutils-2.41-2.zncgsl7.6.src.rpm"}]}]}

CVE

参考