Количество 16
Количество 16
BDU:2026-04785
Уязвимость демона cupsd сервера печати CUPS, позволяющая нарушителю выполнить произвольный код
CVE-2026-34980
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.
CVE-2026-34980
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.
CVE-2026-34980
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.
CVE-2026-34980
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-34980
OpenPrinting CUPS is an open source printing system for Linux and othe ...
RLSA-2026:39316
Moderate: cups security update
RLSA-2026:39302
Moderate: cups security update
RLSA-2026:36733
Moderate: cups security update
ELSA-2026-39316
ELSA-2026-39316: cups security update (MODERATE)
ELSA-2026-39302
ELSA-2026-39302: cups security update (MODERATE)
ELSA-2026-36733
ELSA-2026-36733: cups security update (MODERATE)
SUSE-SU-2026:1617-1
Security update for cups
SUSE-SU-2026:2718-1
Security update for cups
SUSE-SU-2026:2732-1
Security update for cups
openSUSE-SU-2026:20812-1
Security update for cups
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04785 Уязвимость демона cupsd сервера печати CUPS, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-34980 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34980 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches. | CVSS3: 6.4 | 1% Низкий | 4 месяца назад | |
CVE-2026-34980 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network | 1% Низкий | 4 месяца назад | ||
CVE-2026-34980 OpenPrinting CUPS is an open source printing system for Linux and othe ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
RLSA-2026:39316 Moderate: cups security update | 1% Низкий | 16 дней назад | ||
RLSA-2026:39302 Moderate: cups security update | 1% Низкий | 16 дней назад | ||
RLSA-2026:36733 Moderate: cups security update | 1% Низкий | 23 дня назад | ||
ELSA-2026-39316 ELSA-2026-39316: cups security update (MODERATE) | 18 дней назад | |||
ELSA-2026-39302 ELSA-2026-39302: cups security update (MODERATE) | 16 дней назад | |||
ELSA-2026-36733 ELSA-2026-36733: cups security update (MODERATE) | 24 дня назад | |||
SUSE-SU-2026:1617-1 Security update for cups | 3 месяца назад | |||
SUSE-SU-2026:2718-1 Security update for cups | около 1 месяца назад | |||
SUSE-SU-2026:2732-1 Security update for cups | 29 дней назад | |||
openSUSE-SU-2026:20812-1 Security update for cups | 2 месяца назад |
Уязвимостей на страницу