← Back

CVE-2021-25317

nvd nist
Published: May 5, 2021Modified: Jun 17, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.

Affected (7)

Products: Suse: Cups · Fedoraproject: Fedora
1 product
Cups
1 product
Fedora
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.9
Running on/withPlatform Versions
Suse
Linux Enterprise Server
Version 11 sp4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
1 platform
Running on/withPlatform Versions
Suse
Manager Server
Version 4.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.7.5
Running on/withPlatform Versions
Suse
Openstack Cloud Crowbar
Version 9.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.2.7
Running on/withPlatform Versions
Opensuse
Leap
Version 15.2
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.3.3op2-2.1
Running on/withPlatform Versions
Opensuse
Factory
All versions

Timeline

No history available yet.