Lucene search

K
osvGoogleOSV:USN-5454-1
HistoryMay 31, 2022 - 11:29 a.m.

cups vulnerabilities

2022-05-3111:29:49
Google
osv.dev
14
cups
secret key
web interface
remote attacker
arbitrary code
memory operations
ipp printing
denial of service
sensitive information
ubuntu 18.04 lts
ubuntu 20.04 lts
cve-2022-26691
cve-2019-8842
cve-2020-10001
software

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

43.6%

Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)

It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)