CVE-2018-4180External Control of Critical State Data in Cups

Severity
7.8HIGHNVD
OSV5.3
EPSS
0.1%
top 69.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateMay 13

Description

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

debiandebian/cups< cups 2.2.8-2 (bookworm)
NVDapple/mac_os_x< 10.13.5
Debianapple/cups< 2.2.8-2+3
Ubuntuapple/cups< 1.7.2-0ubuntu1.10+2

Also affects: Debian Linux 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04

🔴Vulnerability Details

3
GHSA
GHSA-jwrm-4wqq-pfgh: In macOS High Sierra before 102022-05-13
OSV
CVE-2018-4180: In macOS High Sierra before 102019-01-11
OSV
cups vulnerabilities2018-07-11

📋Vendor Advisories

4
Ubuntu
CUPS vulnerabilities2018-07-11
Apple
CVE-2018-4180: macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan2018-06-01
Red Hat
cups: Local privilege escalation to root due to insecure environment variable handling2018-05-09
Debian
CVE-2018-4180: cups - In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was ad...2018

💬Community

3
Bugzilla
CVE-2018-4180 CVE-2018-4181 CVE-2018-4182 CVE-2018-4183 cups: various flaws [fedora-all]2018-07-23
Bugzilla
CVE-2018-4180 cups: Local privilege escalation to root due to insecure environment variable handling2018-07-23
Bugzilla
CVE-2018-4181 cups: Manipulation of cupsd.conf by a local attacker resulting in limited reads of arbitrary files as root2018-07-23