PT-2018-1823 · Apple+5 · Cups+5
Jann Horn
·
Publicado
2017-02-27
·
Atualizado
2020-10-20
·
CVE-2017-18190
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
CUPS versions prior to 2.2.2
Description:
The issue allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding, potentially disrupting data integrity. This is due to a localhost.localdomain whitelist entry in the valid host() function in scheduler/client.c. The localhost.localdomain name is often resolved via a DNS server.
Recommendations:
For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the CUPS daemon to minimize the risk of exploitation. Avoid using the
valid host() function in conjunction with DNS rebinding until the issue is resolved.Exploit
Correção
RCE
Authentication Bypass by Spoofing
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Cups
Centos
Red Hat
Suse
Ubuntu