CVE-2008-5184
published 2008-11-21CVE-2008-5184: The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.67%
88.3th percentile
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.7 | — |
| apple | cups | <= 1.3.9 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2009-01-12·CVSS 7.5
CVE-2008-5183 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that CUPS didn't properly handle adding a large number of RSS
subscriptions. A local user could exploit this and cause CUPS to crash, leading
to a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and
8.10. (CVE-2008-5183)
It was discovered that CUPS did not authenticate users when adding and
cancelling RSS subscriptions. An unprivileged local user could bypass intended
restrictions and add a large number of RSS subscriptions. This issue only
applied to Ubuntu 7.10 and 8.04 LTS. (CVE-2008-5184)
It was discovered that the PNG filter in CUPS did not properly handle certain
malformed images. If a user or automated system were tricked into opening a
crafted PNG image file, a remote attacker could
Red Hat
cups: DoS (daemon crash) caused by the large number of subscriptions
vendor_redhat·2008-11-15·CVSS 7.5
CVE-2008-5183 [HIGH] cups: DoS (daemon crash) caused by the large number of subscriptions
cups: DoS (daemon crash) caused by the large number of subscriptions
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
Red Hat
cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
vendor_redhat·2008-03-27·CVSS 10.0
CVE-2008-5184 [CRITICAL] cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
Statement: Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3, 4, or 5. Versions shipped do not support RSS subscriptions.
Debian
CVE-2008-5183: cups - cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attacker...
vendor_debian·2008·CVSS 7.5
CVE-2008-5183 [HIGH] CVE-2008-5183: cups - cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attacker...
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
Scope: local
bookworm: resolved (fixed in 1.3.9-13)
bullseye: resolved (fixed in 1.3.9-13)
forky: resolved (fixed in 1.3.9-13)
sid: resolved (fixed in 1.3.9-13)
trixie: resolved (fixed in 1.3.9-13)
Debian
CVE-2008-5184: cups - The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username...
vendor_debian·2008·CVSS 10.0
CVE-2008-5184 [CRITICAL] CVE-2008-5184: cups - The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username...
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
Scope: local
bookworm: resolved (fixed in 1.3.8-1)
bullseye: resolved (fixed in 1.3.8-1)
forky: resolved (fixed in 1.3.8-1)
sid: resolved (fixed in 1.3.8-1)
trixie: resolved (fixed in 1.3.8-1)
GHSA
GHSA-xmmc-fgrf-gp3v: The web interface (cgi-bin/admin
ghsa_unreviewed·2022-05-17
CVE-2008-5184 [HIGH] GHSA-xmmc-fgrf-gp3v: The web interface (cgi-bin/admin
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
GHSA
GHSA-9pqm-v858-jg26: cupsd in CUPS 1
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2008-5183 [CRITICAL] CWE-476 GHSA-9pqm-v858-jg26: cupsd in CUPS 1
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
OSV
CVE-2008-5183: cupsd in CUPS 1
osv·2008-11-21·CVSS 7.5
CVE-2008-5183 [HIGH] CVE-2008-5183: cupsd in CUPS 1
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
OSV
CVE-2008-5184: The web interface (cgi-bin/admin
osv·2008-11-21·CVSS 10.0
CVE-2008-5184 [CRITICAL] CVE-2008-5184: The web interface (cgi-bin/admin
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5184 cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
bugzilla·2008-12-01·CVSS 10.0
CVE-2008-5184 [CRITICAL] CVE-2008-5184 cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
CVE-2008-5184 cups: improper use of the 'guest' username in the web UI, when user not logged on to the server
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5184 to
the following vulnerability:
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the
guest username when a user is not logged on to the web server, which
makes it easier for remote attackers to bypass intended policy and
conduct CSRF attacks via the (1) add and (2) cancel RSS subscription
functions.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5184
http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/
http://www.openwall.com/lists/oss-security/2008/11/19/3
Patch:
http://www.cups.org/str.php?L2774
Discussion:
This issue did not affect cups versions as shipped with Red
Bugzilla
CVE-2008-5183 cups: DoS (daemon crash) caused by the large number of subscriptions
bugzilla·2008-12-01·CVSS 7.5
CVE-2008-5183 [HIGH] CVE-2008-5183 cups: DoS (daemon crash) caused by the large number of subscriptions
CVE-2008-5183 cups: DoS (daemon crash) caused by the large number of subscriptions
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5183 to
the following vulnerability:
cupsd in CUPS before 1.3.8 allows local users, and possibly remote
attackers, to cause a denial of service (daemon crash) by adding a
large number of RSS Subscriptions, which triggers a NULL pointer
dereference. NOTE: this issue can be triggered remotely by leveraging
CVE-2008-5184.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5183
http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/
https://bugs.launchpad.net/ubuntu/+source/cups/+bug/298241
http://www.openwall.com/lists/oss-security/2008/11/19/3
http://www.openwall.com/lists/oss-security/2008/11/19/4
Patch: See attachment --
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://www.cups.org/str.php?L2774http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/http://www.mandriva.com/security/advisories?name=MDVSA-2009:028http://www.openwall.com/lists/oss-security/2008/11/19/3http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://www.cups.org/str.php?L2774http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/http://www.mandriva.com/security/advisories?name=MDVSA-2009:028http://www.openwall.com/lists/oss-security/2008/11/19/3
2008-11-21
Published