File _patchinfo of Package patchinfo.6717
<patchinfo incident="6717"> <issue id="1081557" tracker="bnc">VUL-0: CVE-2017-18190: cups: A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c inCUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands bysending POST requests to the CUPS daemon in conjunc</issue> <issue id="2017-18190" tracker="cve" /> <category>security</category> <rating>important</rating> <packager>kbabioch</packager> <description>This update for cups fixes the following issues: - CVE-2017-18190: Removed localhost.localdomain from list of trustworthy hosts in scheduler/client.c to avoid arbitrary IPP command execution in conjunction with DNS rebinding. (bsc#1081557) </description> <summary>Security update for cups</summary> </patchinfo>