CVE-2008-0597Software Products Cups vulnerability

CWE-3997 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
6.0%
top 9.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 1

Description

Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDeasy_software_products/cups1.1.17, 1.1.22+1

🔴Vulnerability Details

2
GHSA
GHSA-6r33-h68m-pxhm: Use-after-free vulnerability in CUPS before 12022-05-01
CVEList
CVE-2008-0597: Use-after-free vulnerability in CUPS before 12008-02-26

💥Exploits & PoCs

1
Exploit-DB
w3blabor CMS 3.3.0 - Authentication Bypass2009-01-01

📋Vendor Advisories

2
Red Hat
cups: dereference of free'd memory handling IPP browse requests2008-02-25
Debian
CVE-2008-0597: cups - Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions,...2008

💬Community

1
Bugzilla
CVE-2008-0597 cups: dereference of free'd memory handling IPP browse requests2008-02-21
CVE-2008-0597 — Software Products Cups vulnerability | cvebase