CVE-2002-1367Software Products Cups vulnerability

7 documents7 sources
Severity
10.0CRITICALNVD
EPSS
3.9%
top 11.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26
Latest updateApr 30

Description

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

Debianapple/cups< 1.1.18-1+3
NVDeasy_software_products/cups13 versions+12
NVDapple/mac_os_x10.2, 10.2.2+1

🔴Vulnerability Details

3
GHSA
GHSA-qjpg-cf6h-2fr2: Common Unix Printing System (CUPS) 12022-04-30
CVEList
CVE-2002-1367: Common Unix Printing System (CUPS) 12004-09-01
OSV
CVE-2002-1367: Common Unix Printing System (CUPS) 12002-12-26

📋Vendor Advisories

2
Red Hat
security flaw2002-12-19
Debian
CVE-2002-1367: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...2002

💬Community

1
Bugzilla
CVE-2002-1367 security flaw2018-08-16
CVE-2002-1367 — Software Products Cups vulnerability | cvebase