Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41209
HistoryJul 11, 2023 - 12:56 p.m.

Use-After-Free

2023-07-1112:56:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cups
use-after-free
vulnerability
httpclose
scheduler/client.c
free memory.

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

cups is vulnerable to Use-After-Free. The vulnerability occurs when the httpClose(con->http) function is called within scheduler/client.c. CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before leading to use-after-free.

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%