CVE-2018-6553
published 2018-08-10CVE-2018-6553: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape…
PriorityP343high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.39%
31.1th percentile
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.2.8-5 | 2.2.8-5 |
| apple | cups | >= 0 < 2.2.8-5 | 2.2.8-5 |
| apple | cups | >= 0 < 2.2.8-5 | 2.2.8-5 |
| apple | cups | >= 0 < 2.2.8-5 | 2.2.8-5 |
| apple | cups | >= 0 < 1.7.2-0ubuntu1.10 | 1.7.2-0ubuntu1.10 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.5 | 2.1.3-4ubuntu0.5 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.1 | 2.2.7-1ubuntu2.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < cups 2.2.8-5 (bookworm) | cups 2.2.8-5 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f8v-v7q3-8gqv: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links
ghsa_unreviewed·2022-05-13
CVE-2018-6553 [HIGH] GHSA-2f8v-v7q3-8gqv: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
OSV
CVE-2018-6553: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links
osv·2018-08-10·CVSS 8.8
CVE-2018-6553 [HIGH] CVE-2018-6553: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
OSV
cups vulnerabilities
osv·2018-07-11·CVSS 5.3
CVE-2017-18248 [MEDIUM] cups vulnerabilities
cups vulnerabilities
It was discovered that CUPS incorrectly handled certain print jobs with
invalid usernames. A remote attacker could possibly use this issue to cause
CUPS to crash, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2017-18248)
Dan Bastone discovered that the CUPS dnssd backend incorrectly handled
certain environment variables. A local attacker could possibly use this
issue to escalate privileges. (CVE-2018-4180)
Eric Rafaloff and John Dunlap discovered that CUPS incorrectly handled
certain include directives. A local attacker could possibly use this issue
to read arbitrary files. (CVE-2018-4181)
Dan Bastone discovered that the CUPS AppArmor profile incorrectly confined
the dnssd backend. A local attac
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2018-07-11·CVSS 5.3
CVE-2017-18248 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
It was discovered that CUPS incorrectly handled certain print jobs with
invalid usernames. A remote attacker could possibly use this issue to cause
CUPS to crash, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2017-18248)
Dan Bastone discovered that the CUPS dnssd backend incorrectly handled
certain environment variables. A local attacker could possibly use this
issue to escalate privileges. (CVE-2018-4180)
Eric Rafaloff and John Dunlap discovered that CUPS incorrectly handled
certain include directives. A local attacker could possibly use this issue
to read arbitrary files. (CVE-2018-4181)
Dan Bastone discovered that the CUPS AppArmor
Red Hat
cups: AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
vendor_redhat·2018-05-09·CVSS 8.8
CVE-2018-6553 [HIGH] CWE-270 cups: AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
cups: AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
An AppArmor sandbox bypass has been discovered in cups due to the use of hard links which are not covered by the AppArmor profile. An attacker could use the hard link, if it exists, to execute the referenced backend without sandbox restrictions.
Statement: This issue did not affect the versions of cups as shipped with Red Hat Enterprise Linux as they did no
Debian
CVE-2018-6553: cups - The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of h...
vendor_debian·2018·CVSS 8.8
CVE-2018-6553 [HIGH] CVE-2018-6553: cups - The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of h...
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
Scope: local
bookworm: resolved (fixed in 2.2.8-5)
bullseye: resolved (fixed in 2.2.8-5)
forky: resolved (fixed in 2.2.8-5)
sid: resolved (fixed in 2.2.8-5)
trixie: resolved (fixed in 2.2.8-5)
No detection rules found.
No public exploits indexed.
https://lists.debian.org/debian-lts-announce/2018/07/msg00014.htmlhttps://security.gentoo.org/glsa/201908-08https://usn.ubuntu.com/usn/usn-3713-1https://www.debian.org/security/2018/dsa-4243https://lists.debian.org/debian-lts-announce/2018/07/msg00014.htmlhttps://security.gentoo.org/glsa/201908-08https://usn.ubuntu.com/usn/usn-3713-1https://www.debian.org/security/2018/dsa-4243
2018-08-10
Published