Description
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
▶Debiancups< 1.1.99.b1.r4748-1+3 🔴Vulnerability Details
3GHSAGHSA-f338-5f7m-892w: The directory-services functionality in the scheduler in CUPS 1↗2022-05-02 ▶ CVEListCVE-2009-1196: The directory-services functionality in the scheduler in CUPS 1↗2009-06-09 ▶ OSVCVE-2009-1196: The directory-services functionality in the scheduler in CUPS 1↗2009-06-09 ▶ 📋Vendor Advisories
2Red Hatcups: DoS (stop, crash) by renewing CUPS browse packets↗2009-06-02 ▶ DebianCVE-2009-1196: cups - The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 ...↗2009 ▶ 💬Community
1BugzillaCVE-2009-1196 cups: DoS (stop, crash) by renewing CUPS browse packets↗2009-04-22 ▶