MGASA-2018-0224

Source
https://advisories.mageia.org/MGASA-2018-0224.html
Import Source
https://advisories.mageia.org/MGASA-2018-0224.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0224
Related
Published
2018-05-09T18:33:09Z
Modified
2018-05-09T18:01:17Z
Summary
Updated cups packages fix security vulnerability
Details

CUPS before version 2.2.6 has a vulnerability in the handling of usernames in the scheduler/ipp.c:add_job() function. A remote attacker could exploit this by submitting a print job with an invalid UTF-8 username to cause a crash and subsequent denial of service (CVE-2017-18248).

References
Credits

Affected packages

Mageia:5 / cups

Package

Name
cups
Purl
pkg:rpm/mageia/cups?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.4-1.5.mga5

Ecosystem specific

{
    "section": "core"
}