HIGH
cups: IPP_TAG_UNSUPPORTED handling NULL pointer dereference DoS
Published Jun 9, 2009
7.5
HIGHCVSS 3.1
EPSS 19.63%
Description
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
Affected products
No data.
Configuration 2
OR
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 3
OR
- 4.0
- 5.0
- 6.0
Configuration 4
OR
- ≥ 10.0.0 · < 10.4.11
- ≥ 10.5.0 · < 10.5.8
- ≥ 10.0.0 · < 10.4.11
- ≥ 10.5.0 · < 10.5.8
Configuration 5
OR
- 10.3
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 3
cups-1:1.1.17-13.3.62
Fixed · RHSA-2009:1083
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.32.el4_8.3
Fixed · RHSA-2009:1083
Red Hat Enterprise Linux 5
cups-1:1.3.7-8.el5_3.6
Fixed · RHSA-2009:1082
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | cups-1:1.1.17-13.3.62 | Fixed | RHSA-2009:1083 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.32.el4_8.3 | Fixed | RHSA-2009:1083 |
| Red Hat Enterprise Linux 5 | cups-1:1.3.7-8.el5_3.6 | Fixed | RHSA-2009:1082 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (23)
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html vendor-advisoryx_refsource_SUSEMailing List
- http://secunia.com/advisories/35322 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/35328 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/35340 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/35342 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/35685 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36701 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securitytracker.com/id?1022321 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://support.apple.com/kb/HT3865 x_refsource_CONFIRMThird Party Advisory
- http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability x_refsource_MISCExploitThird Party Advisory
- http://www.debian.org/security/2009/dsa-1811 vendor-advisoryx_refsource_DEBIANBroken LinkThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1082.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2009-1083.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/504032/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/35169 vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-780-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-0949 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=500972 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50926 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-0949
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9631 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2009-0949
| Link | Providers | Tags |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html | vendor-advisoryx_refsource_APPLEMailing List | |
| http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html | vendor-advisoryx_refsource_SUSEMailing List | |
| http://secunia.com/advisories/35322 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/35328 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/35340 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/35342 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/35685 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/36701 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://securitytracker.com/id?1022321 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://support.apple.com/kb/HT3865 | x_refsource_CONFIRMThird Party Advisory | |
| http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability | x_refsource_MISCExploitThird Party Advisory | |
| http://www.debian.org/security/2009/dsa-1811 | vendor-advisoryx_refsource_DEBIANBroken LinkThird Party Advisory | |
| http://www.redhat.com/support/errata/RHSA-2009-1082.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://www.redhat.com/support/errata/RHSA-2009-1083.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://www.securityfocus.com/archive/1/504032/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/35169 | vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/USN-780-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2009-0949 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=500972 | x_refsource_CONFIRMIssue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/50926 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-0949 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9631 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cve.org/CVERecord?id=CVE-2009-0949 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 9, 2009
Updated Aug 7, 2024
Reserved Mar 18, 2009
Link CVE-2009-0949
CISA Vulnrichment
Updated n/a