Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-4180

Опубликовано: 09 мая 2018
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

It was discovered that CUPS allows non-root users to pass environment variables to CUPS backends. Affected backends use attacker-controlled environment variables without proper sanitization. A local attacker, who is part of one of the groups specified in the SystemGroups directive, could use the cupsctl binary to set SetEnv and PassEnv directives and potentially controls the flow of the affected backend, resulting in some cases in arbitrary code execution with root privileges.

Меры по смягчению последствий

Do not add untrusted users to sys and root groups.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cupsWill not fix
Red Hat Enterprise Linux 6cupsWill not fix
Red Hat Enterprise Linux 8cupsNot affected
Red Hat Virtualization 4cupsNot affected
Red Hat Enterprise Linux 7cupsFixedRHSA-2020:105031.03.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-642
https://bugzilla.redhat.com/show_bug.cgi?id=1607282cups: Local privilege escalation to root due to insecure environment variable handling

EPSS

Процентиль: 41%
0.0019
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS3: 7.8
nvd
около 7 лет назад

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS3: 7.8
debian
около 7 лет назад

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This is ...

CVSS3: 7.8
github
больше 3 лет назад

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость сервера печати CUPS, связанная с ошибками авторизации, позволяющая нарушителю выполнить произвольный код с привилегиями root

EPSS

Процентиль: 41%
0.0019
Низкий

6.7 Medium

CVSS3