CVE-2020-10001
published 2021-04-02CVE-2020-10001: An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.04%
60.4th percentile
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.3op2-1 | 2.3.3op2-1 |
| apple | cups | >= 0 < 2.3.3op2-1 | 2.3.3op2-1 |
| apple | cups | >= 0 < 2.3.3op2-1 | 2.3.3op2-1 |
| apple | cups | >= 0 < 2.3.3op2-1 | 2.3.3op2-1 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.9 | 2.2.7-1ubuntu2.9 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.2 | 2.3.1-9ubuntu1.2 |
| apple | cups | >= 0 < 2.4.1op1-1ubuntu4.1 | 2.4.1op1-1ubuntu4.1 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11+esm1 | 2.1.3-4ubuntu0.11+esm1 |
| apple | mac_os_x | < 11.1.0 | 11.1.0 |
| apple | macos | >= unspecified < 11.1 | 11.1 |
| debian | cups | < cups 2.3.3op2-1 (bookworm) | cups 2.3.3op2-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
GHSA
GHSA-jj3c-g89r-fx84: An input validation issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2020-10001 [MEDIUM] CWE-20 GHSA-jj3c-g89r-fx84: An input validation issue was addressed with improved memory handling
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
OSV
CVE-2020-10001: An input validation issue was addressed with improved memory handling
osv·2021-04-02·CVSS 5.5
CVE-2020-10001 [MEDIUM] CVE-2020-10001: An input validation issue was addressed with improved memory handling
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2020-10001 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, C
Red Hat
cups: access to uninitialized buffer in ipp.c
vendor_redhat·2021-02-01·CVSS 5.5
CVE-2020-10001 [MEDIUM] CWE-120 cups: access to uninitialized buffer in ipp.c
cups: access to uninitialized buffer in ipp.c
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
Package: cups (Red Hat Enterprise Linux 5) - Out of support scope
Package: cups (Red Hat Enterprise Linux 6) - Out of support scope
Package: cups (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2020-10001: cups - An input validation issue was addressed with improved memory handling. This issu...
vendor_debian·2020·CVSS 5.5
CVE-2020-10001 [MEDIUM] CVE-2020-10001: cups - An input validation issue was addressed with improved memory handling. This issu...
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
Scope: local
bookworm: resolved (fixed in 2.3.3op2-1)
bullseye: resolved (fixed in 2.3.3op2-1)
forky: resolved (fixed in 2.3.3op2-1)
sid: resolved (fixed in 2.3.3op2-1)
trixie: resolved (fixed in 2.3.3op2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-02
Published