Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1158

Опубликовано: 26 июн. 2015
Источник: ubuntu
Приоритет: high
EPSS Высокий
CVSS2: 10

Описание

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

РелизСтатусПримечание
devel

released

2.0.2-3ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.7.2-0ubuntu1.6]]
precise

released

1.5.3-0ubuntu8.7
trusty

released

1.7.2-0ubuntu1.6
trusty/esm

DNE

trusty was released [1.7.2-0ubuntu1.6]
upstream

needs-triage

utopic

released

1.7.5-3ubuntu3.2
vivid

released

2.0.2-1ubuntu3.1
vivid/stable-phone-overlay

released

2.0.2-1ubuntu3.1
vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 99%
0.76998
Высокий

10 Critical

CVSS2

Связанные уязвимости

redhat
около 10 лет назад

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

nvd
около 10 лет назад

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

debian
около 10 лет назад

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 ...

github
больше 3 лет назад

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

fstec
около 10 лет назад

Уязвимость сервера печати CUPS, позволяющая нарушителю изменить файл конфигурации устройства или выполнить произвольный код

EPSS

Процентиль: 99%
0.76998
Высокий

10 Critical

CVSS2