Do your applications use this vulnerable package?
Test your applications
Overview
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2017-15400
- CWE
- CWE-93
- Snyk ID
- SNYK-DEBIAN9-CUPS-364696
- Disclosed
- 07 Feb, 2018
- Published
- 07 Feb, 2018