Vulnerability Description
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Cups | < 2.2.2 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1048ExploitIssue TrackingThird Party Advisory
- https://github.com/apple/cups/commit/afa80cb2b457bf8d64f775bed307588610476c41PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00023.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3577-1/Third Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1048ExploitIssue TrackingThird Party Advisory
- https://github.com/apple/cups/commit/afa80cb2b457bf8d64f775bed307588610476c41PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00023.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3577-1/Third Party Advisory
FAQ
What is CVE-2017-18190?
CVE-2017-18190 is a vulnerability with a CVSS score of 7.5 (HIGH). A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon...
How severe is CVE-2017-18190?
CVE-2017-18190 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18190?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Cups, Debian Debian Linux, Canonical Ubuntu Linux.