CVE-2017-18190
Summary
| CVE | CVE-2017-18190 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-16 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3577-1: CUPS vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1288-1] cups security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Don't treat "localhost.localdomain" as an allowed replacement for loc… · apple/cups@afa80cb · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| 1048 -
CUPS: incorrect whitelist permits DNS rebinding attacks -
project-zero -
Monorail |
MISC |
bugs.chromium.org |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1412-1] cups security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377258 Alibaba Cloud Linux Security Update for cups (ALINUX2-SA-2020:0122)