Vulnerability Description
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Cups | <= 1.3.9 |
| Apple | Mac Os X | < 10.5.6 |
| Apple | Mac Os X Server | < 10.5.6 |
| Opensuse | Opensuse | 11.0 |
| Debian | Debian Linux | 5.0 |
Related Weaknesses (CWE)
References
- http://lab.gnucitizen.org/projects/cups-0dayBroken Link
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlMailing List
- http://secunia.com/advisories/33937Broken Link
- http://secunia.com/advisories/43521Broken Link
- http://support.apple.com/kb/HT3438Third Party Advisory
- http://www.debian.org/security/2011/dsa-2176Third Party Advisory
- http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:028Broken Link
- http://www.openwall.com/lists/oss-security/2008/11/19/3Mailing List
- http://www.openwall.com/lists/oss-security/2008/11/19/4Mailing List
- http://www.openwall.com/lists/oss-security/2008/11/20/1Mailing List
- http://www.redhat.com/support/errata/RHSA-2008-1029.htmlBroken Link
- http://www.securityfocus.com/bid/32419Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021396Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2008-5183?
CVE-2008-5183 is a vulnerability with a CVSS score of 7.5 (HIGH). cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL poin...
How severe is CVE-2008-5183?
CVE-2008-5183 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5183?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Cups, Apple Mac Os X, Apple Mac Os X Server, Opensuse Opensuse, Debian Debian Linux.