CVE-2019-8842
published 2020-10-27CVE-2019-8842: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security…
PriorityP418low3.3CVSS 3.1
AVLACLPRNUIRSUCNILAN
EPSS
2.03%
79.0th percentile
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.9 | 2.2.7-1ubuntu2.9 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.2 | 2.3.1-9ubuntu1.2 |
| apple | cups | >= 0 < 2.4.1op1-1ubuntu4.1 | 2.4.1op1-1ubuntu4.1 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11+esm1 | 2.1.3-4ubuntu0.11+esm1 |
| apple | mac_os_x | < 10.15.2 | 10.15.2 |
| apple | macos | >= unspecified < 10.15 | 10.15 |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| debian | cups | < cups 2.3.1-12 (bookworm) | cups 2.3.1-12 (bookworm) |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
GHSA
GHSA-3fhw-2p9h-rjgc: A buffer overflow was addressed with improved bounds checking
ghsa_unreviewed·2022-05-24
CVE-2019-8842 [LOW] CWE-120 GHSA-3fhw-2p9h-rjgc: A buffer overflow was addressed with improved bounds checking
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
OSV
CVE-2019-8842: A buffer overflow was addressed with improved bounds checking
osv·2020-10-27·CVSS 3.3
CVE-2019-8842 [LOW] CVE-2019-8842: A buffer overflow was addressed with improved bounds checking
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2020-10001 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, C
Apple
CVE-2019-8842: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 3.3
CVE-2019-8842 [LOW] CVE-2019-8842: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2019-8842
Component: CUPS
Impact: In certain configurations, a remote attacker may be able to submit arbitrary print jobs
Description: A buffer overflow was addressed with improved bounds checking.
Debian
CVE-2019-8842: cups - A buffer overflow was addressed with improved bounds checking. This issue is fix...
vendor_debian·2019·CVSS 3.3
CVE-2019-8842 [LOW] CVE-2019-8842: cups - A buffer overflow was addressed with improved bounds checking. This issue is fix...
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
Scope: local
bookworm: resolved (fixed in 2.3.1-12)
bullseye: resolved (fixed in 2.3.1-12)
forky: resolved (fixed in 2.3.1-12)
sid: resolved (fixed in 2.3.1-12)
trixie: resolved (fixed in 2.3.1-12)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://support.apple.com/en-us/HT210788https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://support.apple.com/en-us/HT210788
2020-10-27
Published