CVE-2008-0882
cups: double free vulnerability in process_browse_data()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
Una vulnerabilidad de doble liberación en la función process_browse_data en CUPS versión 1.3.5, permite a los atacantes remotos causar una denegación de servicio (bloqueo del demonio) y posiblemente ejecutar código arbitrario por medio de paquetes Browse UDP diseñados hacia el puerto cupsd (631/udp), relacionado con una manipulación no especificada de una impresora remota. NOTA: algunos de estos datos fueron obtenidos de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-02-21 CVE Reserved
- 2008-02-21 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://docs.info.apple.com/article.html?artnum=307562 | X_refsource_confirm | |
http://secunia.com/advisories/29132 | Third Party Advisory | |
http://secunia.com/advisories/29251 | Third Party Advisory | |
http://secunia.com/advisories/29420 | Third Party Advisory | |
http://secunia.com/advisories/29485 | Third Party Advisory | |
http://secunia.com/advisories/29603 | Third Party Advisory | |
http://secunia.com/advisories/29634 | Third Party Advisory | |
http://www.cups.org/str.php?L2656 | X_refsource_confirm | |
http://www.securityfocus.com/bid/27906 | Vdb Entry | |
http://www.securitytracker.com/id?1019473 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0623 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0924/references | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9625 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|