CVE-2017-18248: Input Validation
Published Mar 26, 2018
·Updated
Last updated 25 August 2025
Other sources
The addjob function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
— Launchpad
Affected Software
2 affected componentsFixes available
Apple CUPS<2.2.6
debian/cups
2.3.3op2-3+deb11u82.3.3op2-3+deb11u102.4.2-3+deb12u92.4.10-3+deb13u22.4.10-3+deb13u12.4.16-1
Remediation
Event History
Mar 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:16 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:16 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-18248.
2
What is the severity of CVE-2017-18248?
The severity of CVE-2017-18248 is medium with a severity value of 5.3.
3
What is the affected software?
The affected software is cups.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by sending print jobs with an invalid username.
5
How do I fix CVE-2017-18248?
To fix CVE-2017-18248, update to one of the following versions: 2.2.10-6+deb10u6, 2.2.10-6+deb10u9, 2.3.3op2-3+deb11u6, 2.3.3op2-3+deb11u2, 2.4.2-3+deb12u4, 2.4.7-1.