CVE-2010-0302
published 2010-03-05CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.58%
83.6th percentile
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 1.4.4 | 1.4.4 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | cups | >= 0 < 1.4.2-10 | 1.4.2-10 |
| apple | mac_os_x | < 10.5.8 | 10.5.8 |
| apple | mac_os_x | >= 10.6.0 < 10.6.4 | 10.6.4 |
| apple | mac_os_x_server | < 10.5.8 | 10.5.8 |
| apple | mac_os_x_server | >= 10.6.0 < 10.6.4 | 10.6.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < cups 1.4.2-10 (bookworm) | cups 1.4.2-10 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups Incomplete fix for CVE-2009-3553
vendor_redhat·2010-03-03·CVSS 7.5
CVE-2010-0302 [HIGH] cups Incomplete fix for CVE-2009-3553
cups Incomplete fix for CVE-2009-3553
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-03-03·CVSS 7.5
CVE-2009-3553 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the CUPS scheduler did not properly handle certain
network operations. A remote attacker could exploit this flaw and cause the
CUPS server to crash, resulting in a denial of service. This issue only
affected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,
CVE-2010-0302)
Ronald Volgers discovered that the CUPS lppasswd tool could be made to load
localized message strings from arbitrary files by setting an environment
variable. A local attacker could exploit this with a format-string
vulnerability leading to a root privilege escalation. The default compiler
options for Ubuntu 8.10, 9.04 and 9.10 should reduce this vulnerability to
a denial of service. (CVE-2010-0393)
Instructions: In general, a standar
Debian
CVE-2010-0302: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
vendor_debian·2010·CVSS 7.5
CVE-2010-0302 [HIGH] CVE-2010-0302: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ...
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Scope: local
bookworm: resolved (fixed in 1.4.2-10)
bullseye: resolved (fixed in 1.4.2-10)
forky: resolved (fixed in 1.4.2-10)
sid: resolved (fixed in 1.4.2-10)
trixie: resolved (fixed in 1.4.2-10)
GHSA
GHSA-f4w3-fh2q-326p: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2010-0302 [HIGH] CWE-416 GHSA-f4w3-fh2q-326p: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
OSV
CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
osv·2010-03-05·CVSS 7.5
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
No detection rules found.
No public exploits indexed.
http://cups.org/articles.php?L596http://cups.org/str.php?L3490http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037174.htmlhttp://secunia.com/advisories/38785http://secunia.com/advisories/38927http://secunia.com/advisories/38979http://secunia.com/advisories/40220http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.securityfocus.com/bid/38510http://www.securitytracker.com/id?1024124http://www.ubuntu.com/usn/USN-906-1http://www.vupen.com/english/advisories/2010/1481https://bugzilla.redhat.com/show_bug.cgi?id=557775https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11216https://rhn.redhat.com/errata/RHSA-2010-0129.htmlhttp://cups.org/articles.php?L596http://cups.org/str.php?L3490http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037174.htmlhttp://secunia.com/advisories/38785http://secunia.com/advisories/38927http://secunia.com/advisories/38979http://secunia.com/advisories/40220http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.securityfocus.com/bid/38510http://www.securitytracker.com/id?1024124http://www.ubuntu.com/usn/USN-906-1http://www.vupen.com/english/advisories/2010/1481https://bugzilla.redhat.com/show_bug.cgi?id=557775https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11216https://rhn.redhat.com/errata/RHSA-2010-0129.html
2010-03-05
Published