cbcvebase.
CVE-2009-3553
published 2009-11-20

CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
applecups< 1.4.41.4.4
applecups
applecups
applecups>= 0 < 1.4.2-41.4.2-4
applecups>= 0 < 1.4.2-101.4.2-10
applecups>= 0 < 1.4.2-41.4.2-4
applecups>= 0 < 1.4.2-101.4.2-10
applecups>= 0 < 1.4.2-41.4.2-4
applecups>= 0 < 1.4.2-101.4.2-10
applecups>= 0 < 1.4.2-41.4.2-4
applecups>= 0 < 1.4.2-101.4.2-10
applemac_os_x< 10.5.810.5.8
applemac_os_x>= 10.6.0 < 10.6.410.6.4
applemac_os_x>= 10.6.0 < 10.6.210.6.2
applemac_os_x_server< 10.5.810.5.8
applemac_os_x_server>= 10.6.0 < 10.6.410.6.4
applemac_os_x_server>= 10.6.0 < 10.6.210.6.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancups< cups 1.4.2-10 (bookworm)cups 1.4.2-10 (bookworm)
debiancups< cups 1.4.2-4 (bookworm)cups 1.4.2-4 (bookworm)
debiandebian_linux

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH