Back

HIGH

AppArmor cupsd Sandbox Bypass Due to Use of Hard Links

Published Aug 10, 2018

Description

The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of cups as shipped with Red Hat Enterprise Linux as they did not include support for AppArmor.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Aug 10, 2018
Updated Sep 16, 2024
Reserved Feb 2, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 9, 2018