APPLE-SA-2009-09-10-2Vendor advisory
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html CVE-2009-0949
HIGH
CUPS 1.3.9 - 'cups/ipp.c' Null Pointer Dereference Denial of Service
Record summary
CVE-2009-0949 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCUPS 1.3.9 - 'cups/ipp.c' Null Pointer Dereference Denial of ServiceExploitDB exploitby Anibal SaccoNot analyzed1 file
References
Showing 12 of 21SUSE-SR:2009:012Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html 35322Third-party advisory
http://secunia.com/advisories/35322 35328Third-party advisory
http://secunia.com/advisories/35328 35340Third-party advisory
http://secunia.com/advisories/35340 35342Third-party advisory
http://secunia.com/advisories/35342 35685Third-party advisory
http://secunia.com/advisories/35685 36701Third-party advisory
http://secunia.com/advisories/36701 1022321vdb entry
http://securitytracker.com/id?1022321 support.apple.comConfirmation
http://support.apple.com/kb/HT3865 coresecurity.com
http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability DSA-1811Vendor advisory
http://www.debian.org/security/2009/dsa-1811