apple/cups
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 499.4, < 2.4.2 | 6.7 MEDIUM | 7.2 HIGH | ||
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. | ||||
| < 1.5.4-1.1 | 9.8 CRITICAL | 6.8 MEDIUM | ||
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system | ||||
| < 2.2.10 | — | 4.3 MEDIUM | ||
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10. | ||||
| all versions | — | 4.6 MEDIUM | ||
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS. | ||||
| < 2.2.6 | — | 3.5 LOW | ||
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification. | ||||
| < 2.2.2 | — | 5 MEDIUM | ||
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1). | ||||
| < 1.6 | 8.8 HIGH | 5.1 MEDIUM | ||
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name. | ||||
| <= 2.0.2 | — | 4.3 MEDIUM | ||
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/. | ||||
| <= 2.0.2 | — | 10 HIGH | ||
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code. | ||||
| <= 2.0.1 | — | 6.8 MEDIUM | ||
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow. | ||||
| = 1.7.0, = 1.7.1, = 1.7, = 1.7.2, <= 1.7.4, = 1.7.3 | — | 5 MEDIUM | ||
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors. | ||||
| = 1.7.0, = 1.7.1, = 1.7, = 1.7.2, <= 1.7.4, = 1.7.3 | — | 1.9 LOW | ||
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py. | ||||
| = 1.7.4 | — | 1.5 LOW | ||
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537. | ||||
| = 1.7.0, = 1.7.1, = 1.7, = 1.7.2, <= 1.7.3 | — | 1.2 LOW | ||
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/. | ||||
| = 1.1.20, = 1.4, = 1.6.2, = 1.1.5-2, = 1.5.3, = 1.3.9, = 1.1.14, = 1.5.0, = 1.3, = 1.1.12, = 1.1.6-1, = 1.3.3, = 1.1.16, = 1.2.0, = 1.3.1, = 1.4.1, = 1.1.15, = 1.1.23, = 1.5, = 1.7.1, = 1.7.0, = 1.1.18, = 1.1.22, = 1.1.5-1, = 1.3.11, = 1.5.2, = 1.1.19, = 1.2, = 1.2.9, = 1.3.2, = 1.4.6, = 1.6, = 1.1.17, = 1.1.21, = 1.1.3, = 1.1.4, = 1.1.7, = 1.1.8, = 1.2.4, = 1.4.0, = 1.6.4, = 1.6.3, = 1.7, = 1.1, = 1.1.6-2, = 1.2.3, = 1.3.4, = 1.4.8, = 1.1.5, = 1.2.1, = 1.2.10, = 1.2.6, = 1.3.8, = 1.4.4, = 1.1.13, = 1.1.6, = 1.2.11, = 1.2.12, = 1.4.5, = 1.1.1, = 1.1.10, = 1.1.2, = 1.2.5, = 1.3.0, = 1.3.6, = 1.3.7, = 1.4.2, = 1.5.4, = 1.1.6-3, = 1.2.2, = 1.3.5, = 1.4.7, <= 1.7.1, = 1.1.10-1, = 1.1.11, = 1.1.9, = 1.1.9-1, = 1.2.7, = 1.2.8, = 1.3.10, = 1.4.3, = 1.5.1, = 1.6.1 | — | 4.3 MEDIUM | ||
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function. | ||||
| = 1.7.1, = 1.7, <= 1.7.0 | — | 1.2 LOW | ||
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf. | ||||