CVE-2009-0949
09.06.2009, 17:30
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.Enginsight
Vendor | Product | Version |
---|---|---|
apple | cups | 𝑥 < 1.3.10 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
debian | debian_linux | 4.0 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
apple | mac_os_x | 10.0.0 ≤ 𝑥 < 10.4.11 |
apple | mac_os_x | 10.5.0 ≤ 𝑥 < 10.5.8 |
apple | mac_os_x_server | 10.0.0 ≤ 𝑥 < 10.4.11 |
apple | mac_os_x_server | 10.5.0 ≤ 𝑥 < 10.5.8 |
opensuse | opensuse | 10.3 |
suse | linux_enterprise | 9.0 |
suse | linux_enterprise | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References