CVE-2010-2941

CRITICAL

CUPS < 1.4.4 - Use-After-Free via Crafted IPP Request

Title source: llm
STIX 2.1

Description

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

References (29)

Core 29
Core References
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:234
Broken Link x_refsource_confirm
http://support.apple.com/kb/HT4435
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3042
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2010-0811.html
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0866.html
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:232
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2856
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2176
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024662
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42867
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201207-10.xml
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0061
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0535
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1012-1
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:233
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42287
Issue Tracking, Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=624438
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/62882
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43521
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/68951
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44530
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3088

Scores

CVSS v3 9.8
EPSS 0.2135
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (23)
apple/cups < 1.4.4
apple/mac_os_x < 10.5.8
apple/mac_os_x_server < 10.5.8
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 9.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
debian/debian_linux 5.0
fedoraproject/fedora 12
... and 13 more
Published Nov 05, 2010
Tracked Since Feb 18, 2026