11-27-2024, 04:29 PM
(09-24-2024, 10:14 AM)thecaptainjohnson Wrote:
- connect to a malicious IPP server via discovery (cups-browsed): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CWE-940
https://github.com/OpenPrinting/cups-bro...ed.c#L3994
- Returning malicious IPP attributes (cups-browsed, libppd): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N - CWE-20
https://github.com/OpenPrinting/cups-bro...ed.c#L8628
https://github.com/OpenPrinting/libppd/b...tor.c#L353
- Command execution (cups-browsed, cups-filters): 9.9 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L - CWE-94
https://github.com/OpenPrinting/cups-bro...ed.c#L8939
https://github.com/OpenPrinting/cups-fil...rip.c#L983
Is this for real man ?