Security restrictions bypass in CUPS - CVE-2018-6553

 

Security restrictions bypass in CUPS - CVE-2018-6553

Published: July 16, 2018


Vulnerability identifier: #VU13885
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6553
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to unspecified flaw. A remote attacker can invoke the dnssd backend using an alternate name that has been hard linked to dnssd and bypass the AppArmor cupsd sandbox


Affected software

CUPS
Debian Linux
Gentoo Linux

How to mitigate CVE-2018-6553

Update to version 2.2.1.

CUPS - update to 2.2.1

External References

Related Security Bulletins