Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8166

Опубликовано: 12 янв. 2018
Источник: debian

Описание

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cupsunfixedpackage

Примечания

  • Patch: https://bugzilla.redhat.com/attachment.cgi?id=916761

  • Terminal emulators need to perform proper escaping

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

redhat
почти 11 лет назад

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

CVSS3: 8.8
nvd
около 8 лет назад

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

CVSS3: 8.8
github
больше 3 лет назад

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.