CVE-2015-1158 describes a critical vulnerability in CUPS versions prior to 2.0.3, specifically within the add_job function in cupsd. This flaw allows remote attackers to trigger data corruption via crafted IPP_CREATE_JOB or IPP_PRINT_JOB requests, affecting the handling of job-originating-host-name attributes. The vulnerability carries a CVSS score of 10.0, indicating maximum severity. It is easily exploitable over the network with low attack complexity and no authentication required, leading to complete compromise of confidentiality, integrity, and availability, including arbitrary code execution. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, demonstrating remote command execution. The vulnerability has garnered significant community attention and media coverage, with an EPSS score indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.2CPE matchmatch criteria | cpe:2.3:a:cups:cups:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.