CVE-2002-1367
published 2002-12-26CVE-2002-1367: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.68%
88.5th percentile
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| debian | cups | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-12-19·CVSS 10.0
CVE-2002-1367 [CRITICAL] security flaw
security flaw
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
Debian
CVE-2002-1367: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...
vendor_debian·2002·CVSS 10.0
CVE-2002-1367 [CRITICAL] CVE-2002-1367: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed in 1.1.18-1)
trixie: resolved (fixed in 1.1.18-1)
GHSA
GHSA-qjpg-cf6h-2fr2: Common Unix Printing System (CUPS) 1
ghsa_unreviewed·2022-04-30
CVE-2002-1367 [HIGH] GHSA-qjpg-cf6h-2fr2: Common Unix Printing System (CUPS) 1
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
OSV
CVE-2002-1367: Common Unix Printing System (CUPS) 1
osv·2002-12-26·CVSS 10.0
CVE-2002-1367 [CRITICAL] CVE-2002-1367: Common Unix Printing System (CUPS) 1
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6436https://exchange.xforce.ibmcloud.com/vulnerabilities/10908http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6436https://exchange.xforce.ibmcloud.com/vulnerabilities/10908
2002-12-26
Published