{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "state": "PUBLISHED",
        "cveId": "CVE-2021-25317",
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "dateUpdated": "2024-09-17T00:32:16.952Z",
        "dateReserved": "2021-01-19T00:00:00",
        "datePublished": "2021-05-05T09:35:13.321996Z"
    },
    "containers": {
        "cna": {
            "title": "cups: ownership of /var/log/cups allows the lp user to create files as root",
            "datePublic": "2021-04-30T00:00:00",
            "providerMetadata": {
                "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
                "shortName": "suse",
                "dateUpdated": "2023-01-19T00:00:00"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions."
                }
            ],
            "affected": [
                {
                    "vendor": "SUSE",
                    "product": "SUSE Linux Enterprise Server 11-SP4-LTSS",
                    "versions": [
                        {
                            "version": "cups",
                            "status": "affected",
                            "lessThan": "1.3.9",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "vendor": "SUSE",
                    "product": "SUSE Manager Server 4.0",
                    "versions": [
                        {
                            "version": "cups",
                            "status": "affected",
                            "lessThan": "2.2.7",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "vendor": "SUSE",
                    "product": "SUSE OpenStack Cloud Crowbar 9",
                    "versions": [
                        {
                            "version": "cups",
                            "status": "affected",
                            "lessThan": "1.7.5",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "vendor": "openSUSE",
                    "product": "openSUSE Leap 15.2",
                    "versions": [
                        {
                            "version": "cups",
                            "status": "affected",
                            "lessThan": "2.2.7",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "vendor": "openSUSE",
                    "product": "Factory",
                    "versions": [
                        {
                            "version": "cups",
                            "status": "affected",
                            "lessThanOrEqual": "2.3.3op2-2.1",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://bugzilla.suse.com/show_bug.cgi?id=1184161"
                },
                {
                    "name": "FEDORA-2021-dc578ce534",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H74BP746O5NNVCBUTLLZYAFBPESFVECV/"
                },
                {
                    "name": "FEDORA-2021-7b698513d5",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S37IDQGHTORQ3Z6VRDQIGBYVOI27YG47/"
                },
                {
                    "name": "FEDORA-2021-be95e017e7",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWPGZLT3U776Q5YPPSA6LGFWWBDWBVH3/"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Matthias Gerstner of SUSE"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "attackVector": "LOCAL",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "NONE",
                        "baseScore": 3.3,
                        "baseSeverity": "LOW"
                    }
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "lang": "en",
                            "description": "CWE-276: Incorrect Default Permissions",
                            "cweId": "CWE-276"
                        }
                    ]
                }
            ],
            "x_generator": {
                "engine": "Vulnogram 0.0.9"
            },
            "source": {
                "advisory": "https://bugzilla.suse.com/show_bug.cgi?id=1184161",
                "defect": [
                    "1184161"
                ],
                "discovery": "INTERNAL"
            }
        },
        "adp": [
            {
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2024-08-03T20:03:04.109Z"
                },
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://bugzilla.suse.com/show_bug.cgi?id=1184161",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "FEDORA-2021-dc578ce534",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H74BP746O5NNVCBUTLLZYAFBPESFVECV/"
                    },
                    {
                        "name": "FEDORA-2021-7b698513d5",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S37IDQGHTORQ3Z6VRDQIGBYVOI27YG47/"
                    },
                    {
                        "name": "FEDORA-2021-be95e017e7",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWPGZLT3U776Q5YPPSA6LGFWWBDWBVH3/"
                    }
                ]
            }
        ]
    }
}