Input validation error in CUPS - CVE-2014-8166

 

Input validation error in CUPS - CVE-2014-8166

Published: January 12, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37672
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8166
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.


Affected software

CUPS

How to mitigate CVE-2014-8166

Install update from vendor's website.


External References

Related Security Bulletins