Record summary

CVE-2008-5183 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCUPS 1.3.7 - Cross-Site Request Forgery (Add RSS Subscription) Remote CrashExploitDB exploitby Adrian _pagvac_ PastorNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 22