CVE-2009-0164
published 2009-04-24CVE-2009-0164: The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS…
PriorityP430medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
2.91%
85.5th percentile
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.9 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x338-9gp2-578v: The web interface for CUPS before 1
ghsa_unreviewed·2022-05-02
CVE-2009-0164 [MEDIUM] CWE-20 GHSA-x338-9gp2-578v: The web interface for CUPS before 1
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
OSV
CVE-2009-0164: The web interface for CUPS before 1
osv·2009-04-24·CVSS 6.4
CVE-2009-0164 [MEDIUM] CVE-2009-0164: The web interface for CUPS before 1
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
Red Hat
cups: insufficient checking of the HTTP Host: header
vendor_redhat·2009-04-16·CVSS 6.4
CVE-2009-0164 [MEDIUM] cups: insufficient checking of the HTTP Host: header
cups: insufficient checking of the HTTP Host: header
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the security risk. We therefore have no plans to fix this flaw in Red Hat Enterprise Linux 4 and 5.
Package: cups (Red Hat Enterprise Linux 4) - Will not fix
Package: cups (Red Hat Enterprise Linux 5) - Will not fix
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2009-0164: cups - The web interface for CUPS before 1.3.10 does not validate the HTTP Host header ...
vendor_debian·2009·CVSS 6.4
CVE-2009-0164 [MEDIUM] CVE-2009-0164: cups - The web interface for CUPS before 1.3.10 does not validate the HTTP Host header ...
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
Scope: local
bookworm: resolved (fixed in 1.3.10-1)
bullseye: resolved (fixed in 1.3.10-1)
forky: resolved (fixed in 1.3.10-1)
sid: resolved (fixed in 1.3.10-1)
trixie: resolved (fixed in 1.3.10-1)
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=263070http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://support.apple.com/kb/HT3549http://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.cups.org/articles.php?L582http://www.cups.org/str.php?L3118http://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/bid/34665http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://bugzilla.redhat.com/show_bug.cgi?id=490597http://bugs.gentoo.org/show_bug.cgi?id=263070http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://support.apple.com/kb/HT3549http://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.cups.org/articles.php?L582http://www.cups.org/str.php?L3118http://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/bid/34665http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://bugzilla.redhat.com/show_bug.cgi?id=490597
2009-04-24
Published