cbcvebase.
CVE-2017-18248
published 2018-03-26

CVE-2017-18248: The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an…

medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.

Affected

9 ranges
VendorProductVersion rangeFixed in
applecups< 2.2.62.2.6
applecups>= 0 < 2.2.6-12.2.6-1
applecups>= 0 < 2.2.6-12.2.6-1
applecups>= 0 < 2.2.6-12.2.6-1
applecups>= 0 < 2.2.6-12.2.6-1
applecups>= 0 < 1.7.2-0ubuntu1.101.7.2-0ubuntu1.10
applecups>= 0 < 2.1.3-4ubuntu0.52.1.3-4ubuntu0.5
applecups>= 0 < 2.2.7-1ubuntu2.12.2.7-1ubuntu2.1
debiancups< cups 2.2.6-1 (bookworm)cups 2.2.6-1 (bookworm)

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.3MEDIUM