USN-3713-1
Dashboard / Vulnerabilities / USN-3713-1
USN-3713-1
Summary: cups vulnerabilities
Details: It was discovered that CUPS incorrectly handled certain print jobs with invalid usernames. A remote attacker could possibly use this issue to cause CUPS to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2017-18248) Dan Bastone discovered that the CUPS dnssd backend incorrectly handled certain environment variables. A local attacker could possibly use this issue to escalate privileges. (CVE-2018-4180) Eric Rafaloff and John Dunlap discovered that CUPS incorrectly handled certain include directives. A local attacker could possibly use this issue to read arbitrary files. (CVE-2018-4181) Dan Bastone discovered that the CUPS AppArmor profile incorrectly confined the dnssd backend. A local attacker could possibly use this issue to escape confinement. (CVE-2018-6553)
References: https://ubuntu.com/security/notices/USN-3713-1, https://ubuntu.com/security/CVE-2017-18248, https://ubuntu.com/security/CVE-2018-4180, https://ubuntu.com/security/CVE-2018-4181, https://ubuntu.com/security/CVE-2018-6553
Affected packages
Package
Name: cups
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
