Security Features in CUPS - CVE-2015-1158

 

Security Features in CUPS - CVE-2015-1158

Published: June 26, 2015 / Updated: July 29, 2020


Vulnerability identifier: #VU32416
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1158
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.


Affected software

CUPS
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
Fedora
cups (Alpine package)
cups

How to mitigate CVE-2015-1158

Install update from vendor's website.

CUPS - update to 2.0.3
cups (Alpine package) - update to 1.7.4-r2
cups - addressed in versions 1.7.5-17.fc21, 2.0.3-1.fc22

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins