Lucene search

K
osvGoogleOSV:USN-5454-2
HistoryMay 31, 2022 - 7:35 p.m.

cups vulnerabilities

2022-05-3119:35:26
Google
osv.dev
11
cups
usn-5454-1
ubuntu 16.04 esm
joshua mason
administrative web interface
arbitrary code
cve-2022-26691
memory operations
ipp printing
denial of service
sensitive information
ubuntu 18.04 lts
ubuntu 20.04 lts
cve-2019-8842
cve-2020-10001

AI Score

7.9

Confidence

Low

EPSS

0.001

Percentile

43.6%

USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)

It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)