Security restrictions bypass in CUPS - CVE-2018-6553
Published: July 16, 2018
Vulnerability identifier: #VU13885
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6553
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to unspecified flaw. A remote attacker can invoke the dnssd backend using an alternate name that has been hard linked to dnssd and bypass the AppArmor cupsd sandbox
Affected software
CUPS
Debian Linux
Gentoo Linux
Debian Linux
Gentoo Linux
How to mitigate CVE-2018-6553
Update to version 2.2.1.
CUPS - update to 2.2.1