← All CVEs

CVE-2009-0949

high · 7.5

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

7.5
CVSS
19.6%
EPSS (exploit prob.)
97th
EPSS percentile
2009-06-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-908

Affected products

VendorProductAffected versions
applecups< 1.3.10
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
canonicalubuntu_linux9.04
debiandebian_linux4.0
debiandebian_linux5.0
debiandebian_linux6.0
applemac_os_x>= 10.0.0, < 10.4.11
applemac_os_x>= 10.5.0, < 10.5.8
applemac_os_x_server>= 10.0.0, < 10.4.11
applemac_os_x_server>= 10.5.0, < 10.5.8
opensuseopensuse10.3
suselinux_enterprise9.0
suselinux_enterprise10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0949