VDB
WID-SEC-W-2025-2039
WID-SEC-W-2025-2039
PUBLISHED
CVSS 8.699999809265137 HIGH
CUPS (Common Unix Printing System) ist ein Printspooler, der es lokalen und entfernten Benutzern ermöglicht, Druckfunktionen über das Internet Printing Protocol (IPP) zu nutzen.
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell NetWorker Virtual Edition | ||
| IBM App Connect Enterprise <12.0.16 | ||
| Open Source CUPS 2.4.13 | ||
| IBM App Connect Enterprise 12.16.0 | ||
| SUSE Linux | ||
| Ubuntu Linux | ||
| RESF Rocky Linux | ||
| Red Hat Enterprise Linux | ||
| IBM App Connect Enterprise <12.16.0 | ||
| Amazon Linux 2 | ||
| IBM App Connect Enterprise 12.0.16 | ||
| Oracle Linux | ||
| IGEL OS | ||
| Open Source CUPS <2.4.13 | ||
| Dell Avamar | ||
| SUSE openSUSE | ||
| Debian Linux | ||
| Fedora Linux |
Exploit Intelligence
- Custom script to showcase the novel contribution to CVE-2025-58060 (github-poc-repo)
- Custom script to showcase the novel contribution to CVE-2025-58060 (github-poc)
- https://access.redhat.com/errata/RHSA-2025:16590 (circl)
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q3RRE36HNKNUIJTUYCVXGTJPPUXD33V6/ (circl)
- https://lists.debian.org/debian-security-announce/2025/msg00162.html (circl)
- https://lists.debian.org/debian-lts-announce/2025/09/msg00013.html (circl)
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-ef0ad78558 (circl)
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-a83ad46ca7 (circl)
- https://access.redhat.com/errata/RHSA-2025:15700 (circl)
- https://access.redhat.com/errata/RHSA-2025:15701 (circl)
…and 31 more exploits
Timeline
- Sep 11, 2025 CVE Published
- Jan 21, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2039.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2039 advisory
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-4c68-qgrh-rmmq url
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-7qx3-r744-6qv4 url
- https://lists.debian.org/debian-security-announce/2025/msg00162.html url
- https://lists.debian.org/debian-lts-announce/2025/09/msg00013.html url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-ef0ad78558 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-a83ad46ca7 url
- https://access.redhat.com/errata/RHSA-2025:15700 url
- https://access.redhat.com/errata/RHSA-2025:15701 url
- https://access.redhat.com/errata/RHSA-2025:15702 url
- https://ubuntu.com/security/notices/USN-7745-1 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-3596273b51 url
- https://lists.suse.com/pipermail/sle-security-updates/2025-September/022506.html url
- http://linux.oracle.com/errata/ELSA-2025-15701.html url
- https://linux.oracle.com/errata/ELSA-2025-15702.html url
- http://linux.oracle.com/errata/ELSA-2025-15700.html url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HLQNPAXM4G7LSYXWQAXCEFBPXKAZJM6F/ url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q3RRE36HNKNUIJTUYCVXGTJPPUXD33V6/ url
- https://access.redhat.com/errata/RHSA-2025:16592 url
…and 18 more