LWN.net Logo

CUPS: vulnerability in the CUPS IPP implementation

Package(s):cups CVE #(s):CAN-2003-0195
Created:May 27, 2003 Updated:July 22, 2003
Description: Phil D'Amore of Red Hat discovered a vulnerability in the CUPS IPP (Internet Printing Protocol) implementation. The IPP implementation is single-threaded, which means only one request can be serviced at a time. An attacker could make a partial request that does not time out and therefore creates a denial of service. In order to exploit this bug, an attacker must have the ability to make a TCP connection to the IPP port (by default 631).
Alerts:
Conectiva CLA-2003:702 2003-07-22
Gentoo 200306-09 2003-06-14
Debian DSA-317-1 2003-06-11
SuSE SuSE-SA:2003:028 2003-06-06
Yellow Dog YDU-20030602-3 2003-06-02
Mandrake MDKSA-2003:062 2003-05-29
Slackware ssa:2003-149-01 2003-05-29
Red Hat RHSA-2003:171-01 2003-05-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds