CVE-2009-3553
published 2009-11-20CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.91%
89.1th percentile
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 1.4.4 | 1.4.4 |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | >= 0 < 1.4.2-4 | 1.4.2-4 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-4 | 1.4.2-4 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-4 | 1.4.2-4 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-4 | 1.4.2-4 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | mac_os_x | < 10.5.8 | 10.5.8 |
| apple | mac_os_x | >= 10.6.0 < 10.6.4 | 10.6.4 |
| apple | mac_os_x | >= 10.6.0 < 10.6.2 | 10.6.2 |
| apple | mac_os_x_server | < 10.5.8 | 10.5.8 |
| apple | mac_os_x_server | >= 10.6.0 < 10.6.4 | 10.6.4 |
| apple | mac_os_x_server | >= 10.6.0 < 10.6.2 | 10.6.2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < cups 1.4.2-10 (bookworm) | cups 1.4.2-10 (bookworm) |
| debian | cups | < cups 1.4.2-4 (bookworm) | cups 1.4.2-4 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups Incomplete fix for CVE-2009-3553
vendor_redhat·2010-03-03·CVSS 7.5
CVE-2010-0302 [HIGH] cups Incomplete fix for CVE-2009-3553
cups Incomplete fix for CVE-2009-3553
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-03-03·CVSS 7.5
CVE-2009-3553 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the CUPS scheduler did not properly handle certain
network operations. A remote attacker could exploit this flaw and cause the
CUPS server to crash, resulting in a denial of service. This issue only
affected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,
CVE-2010-0302)
Ronald Volgers discovered that the CUPS lppasswd tool could be made to load
localized message strings from arbitrary files by setting an environment
variable. A local attacker could exploit this with a format-string
vulnerability leading to a root privilege escalation. The default compiler
options for Ubuntu 8.10, 9.04 and 9.10 should reduce this vulnerability to
a denial of service. (CVE-2010-0393)
Instructions: In general, a standar
Debian
CVE-2010-0302: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
vendor_debian·2010·CVSS 7.5
CVE-2010-0302 [HIGH] CVE-2010-0302: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Scope: local
bookworm: resolved (fixed in 1.4.2-10)
bullseye: resolved (fixed in 1.4.2-10)
forky: resolved (fixed in 1.4.2-10)
sid: resolved (fixed in 1.4.2-10)
trixie: resolved (fixed in 1.4.2-10)
Red Hat
cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
vendor_redhat·2009-05-15·CVSS 7.5
CVE-2009-3553 [HIGH] CWE-416 cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-3553: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
vendor_debian·2009·CVSS 7.5
CVE-2009-3553 [HIGH] CVE-2009-3553: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.4.2-4)
bullseye: resolved (fixed in 1.4.2-4)
forky: resolved (fixed in 1.4.2-4)
sid: resolved (fixed in 1.4.2-4)
trixie: resolved (fixed in 1.4.2-4)
GHSA
GHSA-qvh7-j2x6-25x5: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
ghsa_unreviewed·2022-05-02
CVE-2009-3553 [MEDIUM] CWE-416 GHSA-qvh7-j2x6-25x5: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-f4w3-fh2q-326p: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2010-0302 [HIGH] CWE-416 GHSA-f4w3-fh2q-326p: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
OSV
CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
osv·2010-03-05·CVSS 7.5
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
OSV
CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
osv·2009-11-20·CVSS 7.5
CVE-2009-3553 [HIGH] CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0302 cups Incomplete fix for CVE-2009-3553
bugzilla·2010-01-22·CVSS 7.5
CVE-2010-0302 [HIGH] CVE-2010-0302 cups Incomplete fix for CVE-2009-3553
CVE-2010-0302 cups Incomplete fix for CVE-2009-3553
Description of problem:
CVE-2009-3553 (bug #530111) has not been completely fixed.
Version-Release number of selected component (if applicable):
Versions known to be affected:
cups-1.3.7-11.el5_4.5 (RHEL-5.4.z)
cups-1.3.7-16.el5 (RHEL-5)
Additional info:
The cause is that the cupsdDoSelect() function uses one of several implementations depending on the underlying select/poll capabilities of the operating system. For kqueue and epoll implementations, cupsdRemoveSelect() does not immediately decrease the reference count for the file descriptor and instead adds it to the cupsd_inactive_fds array. File descriptors in that array are finally dereferenced in cupsdStopSelect() (i.e. program termination).
In Red Hat Enterprise Linux, the epol
Bugzilla
CVE-2009-3553 cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
bugzilla·2009-10-21·CVSS 7.5
CVE-2009-3553 [HIGH] CVE-2009-3553 cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
CVE-2009-3553 cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface
An use-after-free flaw was found in the way CUPS handled references in its
file descriptors handling interface. A remote attacker could, in a
specially-crafted way, query for the list of current print jobs for a
specific printer, leading to a denial of service (cupsd crash).
Upstream bug report:
http://www.cups.org/str.php?L3200 (currently inaccessible)
Reproducer from upstream STR#3200 issue:
1. produce 300 active jobs on the CUPS server.
2. extract client.zip to any directory
3. execute: java -cp "cups-java-client-1.3.jar";. TestCupsGetJobs 10.236.33.136
(replace 10.236.33.136 with your server address)
Discussion:
This issue does NOT affect the versions of cups
CWE
Use After Free
mitre_cwe
CWE-416 Use After Free
CWE-416: Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity. Impact: Modify Memory. The use of previously freed memory may corrupt valid data, if the memory area in question has been allocated and used properly elsewhere.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. If chunk consolidation occurs after the use of previously freed data, the process may crash
CWE
Improper Update of Reference Count
mitre_cwe·CVSS 5.0
[MEDIUM] CWE-911 Improper Update of Reference Count
CWE-911: Improper Update of Reference Count
The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.
Reference counts can be used when tracking how many objects contain a reference to a particular resource, such as in memory management or garbage collection. When the reference count reaches zero, the resource can be de-allocated or reused because there are no more objects that use it. If the reference count accidentally reaches zero, then the resource might be released too soon, even though it is still in use. If all objects no longer use the resource, but the reference count is not zero, then the resource might not ever be released.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability.
http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.htmlhttp://secunia.com/advisories/37360http://secunia.com/advisories/37364http://secunia.com/advisories/38241http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-275230-1http://support.apple.com/kb/HT4004http://www.cups.org/newsgroups.php/newsgroups.php?v5994+gcups.bugshttp://www.cups.org/newsgroups.php/newsgroups.php?v5996+gcups.bugshttp://www.cups.org/newsgroups.php/newsgroups.php?v6055+gcups.bugshttp://www.cups.org/str.php?L3200http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.redhat.com/support/errata/RHSA-2009-1595.htmlhttp://www.securityfocus.com/bid/37048http://www.ubuntu.com/usn/USN-906-1http://www.vupen.com/english/advisories/2010/0173http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=530111https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11183https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00332.htmlhttp://lists.apple.com/archives/security-announce/2010/Jan/msg00000.htmlhttp://secunia.com/advisories/37360http://secunia.com/advisories/37364http://secunia.com/advisories/38241http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-275230-1http://support.apple.com/kb/HT4004http://www.cups.org/newsgroups.php/newsgroups.php?v5994+gcups.bugshttp://www.cups.org/newsgroups.php/newsgroups.php?v5996+gcups.bugshttp://www.cups.org/newsgroups.php/newsgroups.php?v6055+gcups.bugshttp://www.cups.org/str.php?L3200http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.redhat.com/support/errata/RHSA-2009-1595.htmlhttp://www.securityfocus.com/bid/37048http://www.ubuntu.com/usn/USN-906-1http://www.vupen.com/english/advisories/2010/0173http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=530111https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11183https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00332.html
2009-11-20
Published