5.1
CVSSv2

CVE-2014-8166

Published: 12/01/2018 Updated: 23/10/2020
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote malicious users to execute arbitrary code via a crafted printer name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cups cups

Vendor Advisories

A flaw was found in the way the CUPS daemon added shared printers announced through the network A malicious host or user could send a specially crafted UDP packet to a CUPS server that, when processed, could potentially lead to arbitrary code execution with the privileges of the user running the CUPS daemon ...