PT-2018-5811 · Google+1 · Google Chrome+1

Rory Mcnamara

·

Published

2018-02-07

·

Updated

2018-07-13

·

CVE-2017-15400

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Google Chrome OS versions prior to 62.0.3202.74
Description: The issue is related to insufficient restriction of IPP filters in CUPS, allowing a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file. This is also referred to as a printer zeroconfig CRLF issue.
Recommendations: For Google Chrome OS versions prior to 62.0.3202.74, update to version 62.0.3202.74 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15400
DSA-4243-1

Affected Products

Cups
Google Chrome