OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the AuthType
is set to anything but Basic
, if the request contains an Authorization: Basic ...
header, the password is not checked. This results in authentication bypass. Any configuration that allows an AuthType
that is not Basic
is affected. Version 2.4.13 fixes the issue.
{ "vanir_signatures": [ { "digest": { "length": 11512.0, "function_hash": "161101854988671363650603007211864002538" }, "id": "CVE-2025-58060-b088b8ad", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "file": "scheduler/auth.c", "function": "cupsdAuthorize" }, "source": "https://github.com/openprinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221" }, { "digest": { "line_hashes": [ "252342279466869984469687432689811884911", "224178397817989152176278622935806424142", "34023814051622481731660481993435543916", "32886566208854679595142351155717611645", "77695424112154206107361435810581927774", "298653031029906115643324305168188129119", "35827168545682896286695988030117038484", "115174652598934948060790637798026279729", "131496716382430400409608407831702171299", "60729078821255401626836469559924321696" ], "threshold": 0.9 }, "id": "CVE-2025-58060-b8682118", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "scheduler/auth.c" }, "source": "https://github.com/openprinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221" } ] }