CVE-2009-0949
HIGHApple Cups < 1.3.10 - Use of Uninitialized Resource
Title source: ruleDescription
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Anibal Sacco · pythondoslinux
https://www.exploit-db.com/exploits/33020
References (20)
Scores
CVSS v3
7.5
EPSS
0.2057
EPSS Percentile
95.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-908
Status
draft
Affected Products (13)
apple/cups
< 1.3.10
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
debian/debian_linux
apple/mac_os_x
< 10.4.11
apple/mac_os_x_server
< 10.4.11
opensuse/opensuse
suse/linux_enterprise
suse/linux_enterprise
Timeline
Published
Jun 09, 2009
Tracked Since
Feb 18, 2026