CVE-2007-0720Cups vulnerability

11 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
17.1%
top 4.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 1

Description

The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDcups/cups< 1.2.8
Debianapple/cups< 1.2.7-1+3
NVDapple/mac_os_x< 10.4.9

🔴Vulnerability Details

3
GHSA
GHSA-vxfh-xhpf-gvm6: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection2022-05-01
CVEList
CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection2007-03-13
OSV
CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection2007-03-13

📋Vendor Advisories

3
Red Hat
Incomplete fix for CVE-2007-0720 CUPS denial of service2007-07-20
Debian
CVE-2007-0720: cups - The CUPS service on multiple platforms allows remote attackers to cause a denial...2007
Red Hat
security flaw2006-11-13

💬Community

4
Bugzilla
CVE-2007-0720 security flaw2018-08-16
Bugzilla
CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service2007-07-30
Bugzilla
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server2007-03-14
Bugzilla
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server2007-03-14
CVE-2007-0720 — Cups vulnerability | cvebase