Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34980

Опубликовано: 03 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.

РелизСтатусПримечание
devel

pending

2.4.16-1ubuntu3
esm-infra-legacy/xenial

released

2.1.3-4ubuntu0.11+esm13
esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2.4.1op1-1ubuntu4.20
noble

released

2.4.7-1.2ubuntu7.13
questing

released

2.4.12-0ubuntu3.9
resolute

released

2.4.16-1ubuntu1.2
upstream

released

2.4.17

Показывать по

EPSS

Процентиль: 40%
0.00502
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.

CVSS3: 7.5
nvd
4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.

msrc
4 месяца назад

OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network

CVSS3: 7.5
debian
4 месяца назад

OpenPrinting CUPS is an open source printing system for Linux and othe ...

rocky
16 дней назад

Moderate: cups security update

EPSS

Процентиль: 40%
0.00502
Низкий

7.5 High

CVSS3