VDB

ALINUX2-SA-2020%3A0122

ALINUX2-SA-2020%3A0122 PUBLISHED CVSS 5.800000190734863 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2017-18190: A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1). CVE-2019-8675: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVE-2019-8696: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Risk Scores

CVSS 3.0
5.800000190734863
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Affected Products

VendorProductVersions
Alibaba Cloudcups

Timeline

  • Oct 9, 2020 CVE Updated
  • Oct 10, 2020 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›