Oval Definition:oval:com.ubuntu.precise:def:20151158000
Revision Date:2015-06-26Version:1
Title:CVE-2015-1158 on Ubuntu 12.04 LTS (precise) - high.
Description:The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-1158
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'cups' package in precise was vulnerable but has been fixed (note: '1.5.3-0ubuntu8.7').
  • BACK