Record summary

CVE-2009-0949 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCUPS 1.3.9 - 'cups/ipp.c' Null Pointer Dereference Denial of ServiceExploitDB exploitby Anibal SaccoNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 21