CVE-2008-0596Missing Release of Memory after Effective Lifetime in Software Products Cups

Severity
5.0MEDIUMNVD
EPSS
4.4%
top 11.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 1

Description

Memory leak in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a large number of requests to add and remove shared printers.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDeasy_software_products/cups1.1.17, 1.1.22+1

🔴Vulnerability Details

2
GHSA
GHSA-8473-h2r9-j663: Memory leak in CUPS before 12022-05-01
CVEList
CVE-2008-0596: Memory leak in CUPS before 12008-02-26

📋Vendor Advisories

2
Red Hat
cups: memory leak handling IPP browse requests2008-02-25
Debian
CVE-2008-0596: cups - Memory leak in CUPS before 1.1.22, and possibly other versions, allows remote at...2008

💬Community

1
Bugzilla
CVE-2008-0596 cups: memory leak handling IPP browse requests2008-02-21
CVE-2008-0596 — Software Products Cups vulnerability | cvebase