CVE-2017-18190
Last modified
CVE-2017-18190 is a vulnerability of currently unknown severity. A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).. EPSS estimates a 2.98% chance of exploitation in the next 30 days.
Description
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Cups | < 2.2.2 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
References
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1048Exploit, Issue Tracking, Third Party Advisory
- https://github.com/apple/cups/commit/afa80cb2b457bf8d64f775bed307588610476c41Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00023.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3577-1/Third Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1048Exploit, Issue Tracking, Third Party Advisory
- https://github.com/apple/cups/commit/afa80cb2b457bf8d64f775bed307588610476c41Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00023.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00003.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3577-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18190?
How severe is CVE-2017-18190?
How do I fix CVE-2017-18190?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-18185An issue was discovered in QPDF before 7.0.0. There is a lar…
- CVE-2017-18186An issue was discovered in QPDF before 7.0.0. There is an in…
- CVE-2017-18187In ARM mbed TLS before 2.7.0, there is a bounds-check bypass…
- CVE-2017-18188OpenRC opentmpfiles through 0.1.3, when the fs.protected_har…
- CVE-2017-18189In the startread function in xa.c in Sound eXchange (SoX) th…
- CVE-2017-1819Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-18191An issue was discovered in OpenStack Nova 15.x through 15.1.…
- CVE-2017-18192smart/calculator/gallerylock/CalculatorActivity.java in the …
- CVE-2017-18193fs/f2fs/extent_cache.c in the Linux kernel before 4.13 misha…
- CVE-2017-18194SQL injection vulnerability in users/signup.php in the "sign…
- CVE-2017-18195An issue was discovered in tools/conversations/view_ajax.php…5.3
- CVE-2017-18196Leptonica 1.74.4 constructs unintended pathnames (containing…
Are you affected by CVE-2017-18190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
