CVE-2009-0949

HIGH

Apple Cups < 1.3.10 - Use of Uninitialized Resource

Title source: rule

Description

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Anibal Sacco · pythondoslinux
https://www.exploit-db.com/exploits/33020

References (20)

Scores

CVSS v3 7.5
EPSS 0.2057
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-908
Status draft

Affected Products (13)

apple/cups < 1.3.10
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
debian/debian_linux
apple/mac_os_x < 10.4.11
apple/mac_os_x_server < 10.4.11
opensuse/opensuse
suse/linux_enterprise
suse/linux_enterprise

Timeline

Published Jun 09, 2009
Tracked Since Feb 18, 2026