{"id":"CVE-2021-25317","details":"A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.","modified":"2026-08-18T14:45:26.883095Z","published":"2021-05-05T10:15:08.133Z","related":["SUSE-SU-2021:1453-1","SUSE-SU-2021:1454-1","SUSE-SU-2021:14712-1","openSUSE-SU-2021:0638-1","openSUSE-SU-2024:10707-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"32"},{"last_affected":"33"},{"last_affected":"34"}],"source":"CPE_FIELD"},{"cpes":["cpe:2.3:a:suse:cups:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2.3.3op2-2.1"}],"source":"CPE_FIELD","vendor_product":"suse:cups"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWPGZLT3U776Q5YPPSA6LGFWWBDWBVH3/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H74BP746O5NNVCBUTLLZYAFBPESFVECV/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S37IDQGHTORQ3Z6VRDQIGBYVOI27YG47/"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1184161"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cups","events":[{"introduced":"0"},{"fixed":"f8e258e65590afa11b3b838cd259c1630a1a0499"},{"fixed":"84c97c051db7de61342461b6333a6bf31830535e"},{"fixed":"b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571"}],"database_specific":{"cpe":"cpe:2.3:a:suse:cups:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.3.9"},{"fixed":"2.2.7"},{"fixed":"1.7.5"}],"source":"CPE_FIELD"}}],"versions":["v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.2rc1","v2.2b2","v2.2b1","release-1.7.4","release-1.7.3","release-1.7.2","release-1.7.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-25317.json","vanir_signatures_modified":"2026-08-18T14:45:26Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["303003890556766610888866419304462353612","291756090946273470268552641955786967954","68591482098550456487232219042758121830","4388077441778181441544835706480494185","171373683608698246604133543052171505769","21982286761353577973948743191797741367","143848903433225557252889511556677097719","67769230696771806565077967946060306036","300047019403988043631328124249423493925"]},"id":"CVE-2021-25317-2104f573","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571","target":{"file":"cups/cups.h"}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571","target":{"file":"scheduler/client.c"},"deprecated":false,"digest":{"line_hashes":["205053352418563305066376613023913391755","236096870823453752371163536091485573199","33469241390025520948898365181119731353","74796881880574395968505195768448230358","298704375991029327226813889516672863478","130648743308369052246457664912772543682","70359655328521758953970458861522977589","236141880076909538187338729999518553293","94489074228759981596691939006713876952","37771704108704844086637151182755781625","213093979539852402451663820400269135459","140171898257660116545321247883091303349","22134995000517498851207654545830135713","261420178153917990616019784023445231849","145768033256937380757793104804232350409","117014198786337056833377990944308879588","10787011323854894338203914747323955604","23906996173424717924297765068616328403","82621228629625733641723185394765027467","158310861266317731513230211526126833664","262562802913915756810586927197641626628","153244241286383495427414977135017050005","59411815062431510943226597046382235474","93826797561820227921471851537182943536","277209514393940866363041561340556106550","55365029189114665913559233890948950165","58013747865801902319794588508755375640","129960777116059267426962715060589158804","246663886281287416165591872568476949718","126509230900213812958937864519795447299","29501238794513180549363339331517061327","117331457220768562190658665453723011084","42830302530645333124875636945398675074","5147506907661557941071239616101167675","295630420337395812077490169751693807035","294661571550466008325733524759109640361","142769251559566996019163223424114166616","266425759762152555433529795719635405830","56823427778363356677761159163796143355","228161264602696214147123693250296049680","223117588270997888478669665686335360875","26042855436298978414368911426586979130","317885890309417803404131829706357180436","298608402955908542857391437732551243430","184167844662185262293848697929833420092"],"threshold":0.9},"id":"CVE-2021-25317-31658539","signature_type":"Line"},{"id":"CVE-2021-25317-369de20b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571","target":{"file":"backend/lpd.c"},"deprecated":false,"digest":{"line_hashes":["107434805802401596869135879658761186620","64089697462796517452558244006253532156","80784619067771058005689044994872595924","34000551011340135656503796243610736014","231591630948396174393556616680980131317","20927696405817849831518107552102089672"],"threshold":0.9}},{"deprecated":false,"digest":{"length":4126,"function_hash":"66433352038440194085195916483764431607"},"id":"CVE-2021-25317-7b50dd51","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/84c97c051db7de61342461b6333a6bf31830535e","target":{"function":"http_sspi_find_credentials","file":"cups/tls-sspi.c"}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571","target":{"file":"scheduler/client.c","function":"pipe_command"},"deprecated":false,"digest":{"function_hash":"328725108715556028825553205185040331498","length":6688},"id":"CVE-2021-25317-b4f7791b","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["307112985279991925978928331515558282314","270328792713347568986596821201742819144","154300331090283382335220506091614991562","5522954627274384845318991347701948719","268142757520210058989685695317762607199","81082141193145222630199689536318495596","134910290044528435892823624105212925549","150305668582522756238889283356109015414","137612675822626733142983651723753719278","36625407990571594872305357589419475728","84240418630299097288820502328923464445","168012736320361304367213163699327014115","239498668436469030861996509910774643590","275162306035858992123749550769503102320","175225299305699730400317490442049395946","62251708451964664153535214208131203287","61323042436492022822327855738640716855","163119724495973263728127018702537012615"],"threshold":0.9},"id":"CVE-2021-25317-efbe3782","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/84c97c051db7de61342461b6333a6bf31830535e","target":{"file":"cups/tls-sspi.c"}},{"deprecated":false,"digest":{"function_hash":"214292570993240516196652283700475674138","length":4195},"id":"CVE-2021-25317-f8bbf4ee","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/b60086f8ae7ff126ecb97cf6d400d6d4a5c6f571","target":{"file":"scheduler/client.c","function":"get_file"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}