PublicDateAtUSN: 2018-03-26 Candidate: CVE-2017-18248 PublicDate: 2018-03-26 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18248 https://github.com/apple/cups/releases/tag/v2.2.6 https://security.cucumberlinux.com/security/details.php?id=346 https://ubuntu.com/security/notices/USN-3713-1 Description: The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification. Ubuntu-Description: Notes: Bugs: https://github.com/apple/cups/issues/5143 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H [5.3 MEDIUM] Patches_cups: upstream: https://github.com/apple/cups/commit/49fa4983f25b64ec29d548ffa3b9782426007df3 upstream_cups: released (2.2.6-1) precise/esm_cups: DNE trusty_cups: released (1.7.2-0ubuntu1.10) trusty/esm_cups: DNE (trusty was released [1.7.2-0ubuntu1.10]) xenial_cups: released (2.1.3-4ubuntu0.5) esm-infra/xenial_cups: released (2.1.3-4ubuntu0.5) artful_cups: released (2.2.4-7ubuntu3.1) bionic_cups: not-affected (2.2.6-5) devel_cups: not-affected (2.2.6-5)