The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting database, which allows remote attackers to execute arbitrary code via a man-in-the-middle (MITM) attack that modifies packages or repositories.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade system-config-printer | Jul 30, 2024 | Nov 29, 2011 |
| Suse | — | Upgrade python3-cupshelpersUpgrade udev-configure-printerUpgrade system-config-printer-langUpgrade system-config-printer-common-langUpgrade system-config-printer-dbus-serviceUpgrade system-config-printerUpgrade system-config-printer-commonUpgrade system-config-printer-appletUpgrade python-cupshelpers | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python-cupshelpers | Nov 8, 2024 | Nov 29, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub