V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-4336
DEB
Medium

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execu…

CVSS
5.8
Medium
EPSS
0.01
p60
Published
2014-01-01
Updated
2014-01-01
Description

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

Tags · CWE
CWE-77
CAPEC-15
CAPEC-40
CAPEC-43
CAPEC-75
CAPEC-76
CAPEC-136
CAPEC-183
CAPEC-248
Affected products
Cups-filters ≤ 1.0.52
CVSS vector
AV:A/AC:L/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.011 · p60
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cups-filtersTracked
cups-filtersTracked
cups-filtersTracked
cups-filters*Tracked
Source databases
DEB
CVE
UBU