CVE-2017-18190: High severity Apple CUPS vulnerability
Published Feb 16, 2018
·Updated
A localhost.localdomain whitelist entry in validhost() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).
Affected Software
6 affected componentsFixes available
Apple CUPS<2.2.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
debian/cups
2.3.3op2-3+deb11u82.3.3op2-3+deb11u102.4.2-3+deb12u92.4.10-3+deb13u22.4.10-3+deb13u12.4.16-1
Remediation
Event History
Feb 16, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 5, 2024
Data Sourced
via Launchpad·09:25 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:14 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:15 PM
DescriptionAffected Software