Lucene search

K
nvd[email protected]NVD:CVE-2010-2432
HistoryJun 22, 2010 - 8:30 p.m.

CVE-2010-2432

2010-06-2220:30:01
CWE-399
web.nvd.nist.gov
3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

8.3

Confidence

High

EPSS

0.006

Percentile

78.4%

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.

Affected configurations

Nvd
Node
applecupsRange1.4.3
OR
applecupsMatch1.1
OR
applecupsMatch1.1.1
OR
applecupsMatch1.1.2
OR
applecupsMatch1.1.3
OR
applecupsMatch1.1.4
OR
applecupsMatch1.1.5
OR
applecupsMatch1.1.5-1
OR
applecupsMatch1.1.5-2
OR
applecupsMatch1.1.6
OR
applecupsMatch1.1.6-1
OR
applecupsMatch1.1.6-2
OR
applecupsMatch1.1.6-3
OR
applecupsMatch1.1.7
OR
applecupsMatch1.1.8
OR
applecupsMatch1.1.9
OR
applecupsMatch1.1.9-1
OR
applecupsMatch1.1.10
OR
applecupsMatch1.1.10-1
OR
applecupsMatch1.1.11
OR
applecupsMatch1.1.12
OR
applecupsMatch1.1.13
OR
applecupsMatch1.1.14
OR
applecupsMatch1.1.15
OR
applecupsMatch1.1.16
OR
applecupsMatch1.1.17
OR
applecupsMatch1.1.18
OR
applecupsMatch1.1.19
OR
applecupsMatch1.1.19rc1
OR
applecupsMatch1.1.19rc2
OR
applecupsMatch1.1.19rc3
OR
applecupsMatch1.1.19rc4
OR
applecupsMatch1.1.19rc5
OR
applecupsMatch1.1.20
OR
applecupsMatch1.1.20rc1
OR
applecupsMatch1.1.20rc2
OR
applecupsMatch1.1.20rc3
OR
applecupsMatch1.1.20rc4
OR
applecupsMatch1.1.20rc5
OR
applecupsMatch1.1.20rc6
OR
applecupsMatch1.1.21
OR
applecupsMatch1.1.21rc1
OR
applecupsMatch1.1.21rc2
OR
applecupsMatch1.1.22
OR
applecupsMatch1.1.22rc1
OR
applecupsMatch1.1.22rc2
OR
applecupsMatch1.1.23
OR
applecupsMatch1.1.23rc1
OR
applecupsMatch1.2b1
OR
applecupsMatch1.2b2
OR
applecupsMatch1.2rc1
OR
applecupsMatch1.2rc2
OR
applecupsMatch1.2rc3
OR
applecupsMatch1.2.0
OR
applecupsMatch1.2.1
OR
applecupsMatch1.2.2
OR
applecupsMatch1.2.3
OR
applecupsMatch1.2.4
OR
applecupsMatch1.2.5
OR
applecupsMatch1.2.6
OR
applecupsMatch1.2.7
OR
applecupsMatch1.2.8
OR
applecupsMatch1.2.9
OR
applecupsMatch1.2.10
OR
applecupsMatch1.2.11
OR
applecupsMatch1.2.12
OR
applecupsMatch1.3b1
OR
applecupsMatch1.3rc1
OR
applecupsMatch1.3rc2
OR
applecupsMatch1.3.0
OR
applecupsMatch1.3.1
OR
applecupsMatch1.3.2
OR
applecupsMatch1.3.3
OR
applecupsMatch1.3.4
OR
applecupsMatch1.3.5
OR
applecupsMatch1.3.6
OR
applecupsMatch1.3.7
OR
applecupsMatch1.3.8
OR
applecupsMatch1.3.9
OR
applecupsMatch1.3.10
OR
applecupsMatch1.3.11
OR
applecupsMatch1.4.0
OR
applecupsMatch1.4.1
OR
applecupsMatch1.4.2

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

8.3

Confidence

High

EPSS

0.006

Percentile

78.4%