PT-2018-5811 · Google+1 · Google Chrome+1
Rory Mcnamara
·
Published
2018-02-07
·
Updated
2018-07-13
·
CVE-2017-15400
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Google Chrome OS versions prior to 62.0.3202.74
Description:
The issue is related to insufficient restriction of IPP filters in CUPS, allowing a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file. This is also referred to as a printer zeroconfig CRLF issue.
Recommendations:
For Google Chrome OS versions prior to 62.0.3202.74, update to version 62.0.3202.74 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cups
Google Chrome