Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-4243-1 Critical: CUPS Command Exec And Escalation

debian
Calendar Grey July 11, 2018
Debian Logo
A series of security flaws have been found in CUPS, necessitating immediate measures to protect your Debian installation.
Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System

Summary

CVE-2017-15400

Rory McNamara discovered that an attacker is able to execute arbitrary
commands (with the privilege of the CUPS daemon) by setting a
malicious IPP server with a crafted PPD file.

CVE-2018-4180

Dan Bastone of Gotham Digital Science discovered that a local
attacker with access to cupsctl could escalate privileges by setting
an environment variable.

CVE-2018-4181

Eric Rafaloff and John Dunlap of Gotham Digital Science discovered
that a local attacker can perform limited reads of arbitrary files
as root by manipulating cupsd.conf.

CVE-2018-4182

Dan Bastone of Gotham Digital Science discovered that an attacker
with sandboxed root access can execute backends without a sandbox
profile by provoking an error in CUPS' profile creation.

CVE-2018-4183

Dan Bastone and Eric Rafaloff of Gotham Digital Science discovered
that an attacker with sandboxed root access can execute arbitrary
commands as unsandboxed root by modifying /etc/c...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: cups
CVE ID: CVE-2017-15400 CVE-2018-4180 CVE-2018-4181 CVE-2018-4182

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here