Description
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1387-1 | cups security update |
Debian DLA |
DLA-1412-1 | cups security update |
EUVD |
EUVD-2017-9379 | The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification. |
Ubuntu USN |
USN-3713-1 | CUPS vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:13:49.207Z
Reserved: 2018-03-26T00:00:00.000Z
Link: CVE-2017-18248
No data.
Status : Modified
Published: 2018-03-26T17:29:00.207
Modified: 2024-11-21T03:19:40.680
Link: CVE-2017-18248
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN