CVE-2017-18248
published 2018-03-26CVE-2017-18248: The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an…
PriorityP428medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
EPSS
2.25%
81.1th percentile
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 2.2.6 | 2.2.6 |
| apple | cups | >= 0 < 2.2.6-1 | 2.2.6-1 |
| apple | cups | >= 0 < 2.2.6-1 | 2.2.6-1 |
| apple | cups | >= 0 < 2.2.6-1 | 2.2.6-1 |
| apple | cups | >= 0 < 2.2.6-1 | 2.2.6-1 |
| apple | cups | >= 0 < 1.7.2-0ubuntu1.10 | 1.7.2-0ubuntu1.10 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.5 | 2.1.3-4ubuntu0.5 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.1 | 2.2.7-1ubuntu2.1 |
| debian | cups | < cups 2.2.6-1 (bookworm) | cups 2.2.6-1 (bookworm) |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-445m-qfhv-mv64: The add_job function in scheduler/ipp
ghsa_unreviewed·2022-05-14
CVE-2017-18248 [MEDIUM] CWE-20 GHSA-445m-qfhv-mv64: The add_job function in scheduler/ipp
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
OSV
cups vulnerabilities
osv·2018-07-11·CVSS 5.3
CVE-2017-18248 [MEDIUM] cups vulnerabilities
cups vulnerabilities
It was discovered that CUPS incorrectly handled certain print jobs with
invalid usernames. A remote attacker could possibly use this issue to cause
CUPS to crash, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2017-18248)
Dan Bastone discovered that the CUPS dnssd backend incorrectly handled
certain environment variables. A local attacker could possibly use this
issue to escalate privileges. (CVE-2018-4180)
Eric Rafaloff and John Dunlap discovered that CUPS incorrectly handled
certain include directives. A local attacker could possibly use this issue
to read arbitrary files. (CVE-2018-4181)
Dan Bastone discovered that the CUPS AppArmor profile incorrectly confined
the dnssd backend. A local attac
OSV
CVE-2017-18248: The add_job function in scheduler/ipp
osv·2018-03-26·CVSS 5.3
CVE-2017-18248 [MEDIUM] CVE-2017-18248: The add_job function in scheduler/ipp
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2018-07-11·CVSS 5.3
CVE-2017-18248 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
It was discovered that CUPS incorrectly handled certain print jobs with
invalid usernames. A remote attacker could possibly use this issue to cause
CUPS to crash, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2017-18248)
Dan Bastone discovered that the CUPS dnssd backend incorrectly handled
certain environment variables. A local attacker could possibly use this
issue to escalate privileges. (CVE-2018-4180)
Eric Rafaloff and John Dunlap discovered that CUPS incorrectly handled
certain include directives. A local attacker could possibly use this issue
to read arbitrary files. (CVE-2018-4181)
Dan Bastone discovered that the CUPS AppArmor
Red Hat
cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
vendor_redhat·2017-10-16·CVSS 5.3
CVE-2017-18248 [MEDIUM] CWE-20 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Package: cups (Red Hat Enterprise Linux 5) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Package: cups (Red Hat Enterprise Linux 7) - Affected
Package: cups (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2017-18248: cups - The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support...
vendor_debian·2017·CVSS 5.3
CVE-2017-18248 [MEDIUM] CVE-2017-18248: cups - The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support...
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Scope: local
bookworm: resolved (fixed in 2.2.6-1)
bullseye: resolved (fixed in 2.2.6-1)
forky: resolved (fixed in 2.2.6-1)
sid: resolved (fixed in 2.2.6-1)
trixie: resolved (fixed in 2.2.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service [fedora-all]
bugzilla·2018-03-28·CVSS 5.3
CVE-2017-18248 [MEDIUM] CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service [fedora-all]
CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
bugzilla·2018-03-28·CVSS 5.3
CVE-2017-18248 [MEDIUM] CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
CVE-2017-18248 cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service
CUPS before version 2.2.6 has a vulnerability in the handling of usernames in the scheduler/ipp.c:add_job() function. A remote attacker could exploit this by submitting a print job with an invalid UTF-8 username to cause a crash and subsequent denial of service.
External References:
https://security.cucumberlinux.com/security/details.php?id=346
Upstream Issue:
https://github.com/apple/cups/issues/5143
Upstream Patch:
https://github.com/apple/cups/commit/49fa4983f25b64ec29d548ffa3b9782426007df3
Discussion:
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1561298]
---
I've tried to reproduce this, but so far I don't get the crash. I
https://github.com/apple/cups/commit/49fa4983f25b64ec29d548ffa3b9782426007df3https://github.com/apple/cups/issues/5143https://github.com/apple/cups/releases/tag/v2.2.6https://lists.debian.org/debian-lts-announce/2018/05/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlhttps://security.cucumberlinux.com/security/details.php?id=346https://usn.ubuntu.com/3713-1/https://github.com/apple/cups/commit/49fa4983f25b64ec29d548ffa3b9782426007df3https://github.com/apple/cups/issues/5143https://github.com/apple/cups/releases/tag/v2.2.6https://lists.debian.org/debian-lts-announce/2018/05/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlhttps://security.cucumberlinux.com/security/details.php?id=346https://usn.ubuntu.com/3713-1/
2018-03-26
Published