#VU13880 Command injection in CUPS - CVE-2017-15400
Published: July 11, 2018 / Updated: July 16, 2018
CUPS
Apple Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to command injection. A remote unauthenticated attacker can set a malicious IPP server with a crafted PPD file, inject and execute arbitrary commands with the privilege of the CUPS daemon.