Lucene search

K
cve[email protected]CVE-2009-0949
HistoryJun 09, 2009 - 5:30 p.m.

CVE-2009-0949

2009-06-0917:30:00
CWE-908
web.nvd.nist.gov
68
cups
denial of service
remote attackers
ipp
cve-2009-0949

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

Affected configurations

NVD
Node
applecupsRange<1.3.10
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch8.10
OR
canonicalubuntu_linuxMatch9.04
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
applemac_os_xRange10.0.0–10.4.11
OR
applemac_os_xRange10.5.0–10.5.8
OR
applemac_os_x_serverRange10.0.0–10.4.11
OR
applemac_os_x_serverRange10.5.0–10.5.8
Node
opensuseopensuseMatch10.3
OR
suselinux_enterpriseMatch9.0-
OR
suselinux_enterpriseMatch10.0-
CPENameOperatorVersion
apple:cupsapple cupslt1.3.10

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%