Bug 56701 - CUPS "AuthType" not set for CUPS-Get-Document operation
CUPS "AuthType" not set for CUPS-Get-Document operation
Status: NEW
Product: UCS
Classification: Unclassified
Component: Printserver
UCS 5.0
All All
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-10-05 13:09 CEST by office
Modified: 2023-10-05 13:13 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description office 2023-10-05 13:09:42 CEST
While upgrading to UCS 5.0-5 errata829 a cups update to 2.2.10-6+deb10u9 addressing CVE-2023-32360 (ref #56679) was installed.
"apt-listchanges" informed me, that the important part includes setting the AuthType directive

>   Please double check your /etc/cups/cupds.conf file, whether it limits the access to CUPS-Get-Document with something like the following
>  <Limit CUPS-Get-Document>
>    AuthType Default
>    Require user @OWNER @SYSTEM
>    Order deny,allow
>   </Limit>
> (The important line is the 'AuthType Default' in this section)

I checked with my install, but UCR-templates do not set this directive. 

I think UCS should follow upstream fix automatically and leave it to the user, to "downgrade" security on his own.