CVE-2017-18248: Apple Cups

Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.

The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.

Affected products

  • Apple Cups: before 2.2.6 (fixed in 2.2.6)

Published 2018-03-26. Last modified 2026-06-17.