CVE-2017-18248 PUBLISHED

The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.

EPSS 1.00% · 76.9th percentile

Risk Scores

EPSS Score
1.00%
76.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTScups0, 2.1.0-4ubuntu3, 2.1.0-5
Ubuntu:14.04:LTScups1.7.1-5ubuntu5, 1.7.1-5ubuntu6, 1.7.1-5ubuntu7

Timeline

References

Open in Interactive Console →