CVE-2007-0720
published 2007-03-13CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.32%
91.8th percentile
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 1.2.0 | 1.2.0 |
| apple | cups | >= 0 < 1.2.7-1 | 1.2.7-1 |
| apple | cups | >= 0 < 1.2 | 1.2 |
| apple | cups | >= 0 < 1.2.7-1 | 1.2.7-1 |
| apple | cups | >= 0 < 1.2 | 1.2 |
| apple | cups | >= 0 < 1.2.7-1 | 1.2.7-1 |
| apple | cups | >= 0 < 1.2 | 1.2 |
| apple | cups | >= 0 < 1.2.7-1 | 1.2.7-1 |
| apple | cups | >= 0 < 1.2 | 1.2 |
| apple | mac_os_x | < 10.4.9 | 10.4.9 |
| cups | cups | < 1.2.8 | 1.2.8 |
| debian | cups | < cups 1.2 (bookworm) | cups 1.2 (bookworm) |
| debian | cups | < cups 1.2.7-1 (bookworm) | cups 1.2.7-1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxfh-xhpf-gvm6: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection
ghsa_unreviewed·2022-05-01
CVE-2007-0720 [MEDIUM] GHSA-vxfh-xhpf-gvm6: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
GHSA
GHSA-6rcr-7f7h-w6qx: The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspec
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-4045 [MEDIUM] GHSA-6rcr-7f7h-w6qx: The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspec
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
OSV
CVE-2007-4045: The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspec
osv·2007-07-27·CVSS 5.0
CVE-2007-4045 [MEDIUM] CVE-2007-4045: The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspec
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
OSV
CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection
osv·2007-03-13·CVSS 5.0
CVE-2007-0720 [MEDIUM] CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
Red Hat
Incomplete fix for CVE-2007-0720 CUPS denial of service
vendor_redhat·2007-07-20·CVSS 5.0
CVE-2007-4045 [MEDIUM] Incomplete fix for CVE-2007-0720 CUPS denial of service
Incomplete fix for CVE-2007-0720 CUPS denial of service
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
Debian
CVE-2007-4045: cups - The CUPS service, as used in SUSE Linux before 20070720 and other Linux distribu...
vendor_debian·2007·CVSS 5.0
CVE-2007-4045 [MEDIUM] CVE-2007-4045: cups - The CUPS service, as used in SUSE Linux before 20070720 and other Linux distribu...
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
Scope: local
bookworm: resolved (fixed in 1.2)
bullseye: resolved (fixed in 1.2)
forky: resolved (fixed in 1.2)
sid: resolved (fixed in 1.2)
trixie: resolved (fixed in 1.2)
Debian
CVE-2007-0720: cups - The CUPS service on multiple platforms allows remote attackers to cause a denial...
vendor_debian·2007·CVSS 5.0
CVE-2007-0720 [MEDIUM] CVE-2007-0720: cups - The CUPS service on multiple platforms allows remote attackers to cause a denial...
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
Scope: local
bookworm: resolved (fixed in 1.2.7-1)
bullseye: resolved (fixed in 1.2.7-1)
forky: resolved (fixed in 1.2.7-1)
sid: resolved (fixed in 1.2.7-1)
trixie: resolved (fixed in 1.2.7-1)
Red Hat
security flaw
vendor_redhat·2006-11-13·CVSS 5.0
CVE-2007-0720 [MEDIUM] security flaw
security flaw
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0720 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2007-0720 [MEDIUM] CVE-2007-0720 security flaw
CVE-2007-0720 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
Bugzilla
CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service
bugzilla·2007-07-30·CVSS 5.0
CVE-2007-4045 [MEDIUM] CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service
CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service
Description of problem:
SUSE-SR:2007:014 (see URL field) reads:
- cups denial of service regression fix
CUPS packages were released to fix another denial of service problem
introduced by the previous Denial of Service Fix for CVE-2007-0720, which was
incomplete.
Version-Release number of selected component (if applicable):
CVE-2007-4045 Affects: RHEL4
CVE-2007-4045 Affects: RHEL5
CVE-2007-4045 Affects: FC6
CVE-2007-4045 Affects: FC7
Discussion:
Created attachment 160266
Patch for CVE-2007-4045 CUPS DoS sucked from SUSE package
---
cups-1.3.4-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
cups-1.2.12-7.fc7 has been pushed to th
Bugzilla
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
bugzilla·2007-03-14·CVSS 5.0
CVE-2007-0720 [MEDIUM] CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
+++ This bug was initially created as a clone of Bug #232241 +++
Description of problem:
CUPS doesn't use separate workers for connections. During SSL
negotiation it does not accept new connections from anyone so
any user can DoS the server with unfinished negotiation.
Version-Release number of selected component (if applicable):
Both 1.2 <= 1.2.7 and 1.1 are affected.
I was able to reproduce on RHEL4, RHEL5.
FC6 (1.2.7) is already fixed.
How reproducible:
SSL support needs to be enabled. Default in 1.2.
Steps to Reproduce:
1. Launch the attached reproducer (eventually modify appropriately)
2. Let it run for at least 10 secs (to ensure that the server is not patched)
3. Attempt another co
Bugzilla
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
bugzilla·2007-03-14·CVSS 5.0
CVE-2007-0720 [MEDIUM] CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
Description of problem:
CUPS doesn't use separate workers for connections. During SSL
negotiation it does not accept new connections from anyone so
any user can DoS the server with unfinished negotiation.
Version-Release number of selected component (if applicable):
Both 1.2 <= 1.2.7 and 1.1 are affected.
I was able to reproduce on RHEL4, RHEL5.
FC6 (1.2.7) is already fixed.
How reproducible:
SSL support needs to be enabled. Default in 1.2.
Steps to Reproduce:
1. Launch the attached reproducer (eventually modify appropriately)
2. Let it run for at least 10 secs (to ensure that the server is not patched)
3. Attempt another connection to the CUPS server.
Actual results:
Hang.
Additional i
http://docs.info.apple.com/article.html?artnum=305214http://fedoranews.org/cms/node/2785http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/24479http://secunia.com/advisories/24517http://secunia.com/advisories/24530http://secunia.com/advisories/24660http://secunia.com/advisories/24878http://secunia.com/advisories/24895http://secunia.com/advisories/25119http://secunia.com/advisories/25497http://secunia.com/advisories/26083http://secunia.com/advisories/26413http://security.gentoo.org/glsa/glsa-200703-28.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-194.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:086http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_9_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0123.htmlhttp://www.securityfocus.com/archive/1/463846/100/0/threadedhttp://www.securityfocus.com/bid/22948http://www.securityfocus.com/bid/23127http://www.securitytracker.com/id?1017750http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0930http://www.vupen.com/english/advisories/2007/0949https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243https://issues.rpath.com/browse/RPL-1173https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11046http://docs.info.apple.com/article.html?artnum=305214http://fedoranews.org/cms/node/2785http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/24479http://secunia.com/advisories/24517http://secunia.com/advisories/24530http://secunia.com/advisories/24660http://secunia.com/advisories/24878http://secunia.com/advisories/24895http://secunia.com/advisories/25119http://secunia.com/advisories/25497http://secunia.com/advisories/26083http://secunia.com/advisories/26413http://security.gentoo.org/glsa/glsa-200703-28.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-194.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:086http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_9_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0123.htmlhttp://www.securityfocus.com/archive/1/463846/100/0/threadedhttp://www.securityfocus.com/bid/22948http://www.securityfocus.com/bid/23127http://www.securitytracker.com/id?1017750http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0930http://www.vupen.com/english/advisories/2007/0949https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243https://issues.rpath.com/browse/RPL-1173https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11046
2007-03-13
Published