7.5

CVE-2017-18190

Exploit
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Cups Version < 2.2.2
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.92% 0.856
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://bugs.chromium.org/p/project-zero/issues/detail?id=1048
Third Party Advisory
Exploit
Issue Tracking
https://github.com/apple/cups/commit/afa80cb2b457bf8d64f775bed307588610476c41
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/02/msg00023.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2018/07/msg00003.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/3577-1/
Third Party Advisory