CVE-2010-0542
published 2010-06-21CVE-2010-0542: The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.13%
89.8th percentile
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.3 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-06-21·CVSS 6.0
CVE-2010-0540 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Adrian Pastor and Tim Starling discovered that the CUPS web interface
incorrectly protected against cross-site request forgery (CSRF) attacks. If
an authenticated user were tricked into visiting a malicious website while
logged into CUPS, a remote attacker could modify the CUPS configuration and
possibly steal confidential data. (CVE-2010-0540)
It was discovered that CUPS did not properly handle memory allocations in
the texttops filter. If a user or automated system were tricked into
printing a crafted text file, a remote attacker could cause a denial of
service or possibly execute arbitrary code with privileges of the CUPS user
(lp). (CVE-2010-0542)
Luca Carettoni discovered that the CUPS web interface incorrectly handled
form variables. A remote attacker w
Red Hat
CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
vendor_redhat·2010-06-17·CVSS 6.8
CVE-2010-0542 [MEDIUM] CWE-476 CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0542: cups - The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem...
vendor_debian·2010·CVSS 6.8
CVE-2010-0542 [MEDIUM] CVE-2010-0542: cups - The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem...
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
GHSA
GHSA-cwfp-wwxr-hhq6: The _WriteProlog function in texttops
ghsa_unreviewed·2022-05-02
CVE-2010-0542 [MEDIUM] GHSA-cwfp-wwxr-hhq6: The _WriteProlog function in texttops
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
OSV
CVE-2010-0542: The _WriteProlog function in texttops
osv·2010-06-21·CVSS 6.8
CVE-2010-0542 [MEDIUM] CVE-2010-0542: The _WriteProlog function in texttops
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
bugzilla·2010-11-08·CVSS 5.8
CVE-2010-3879 [MEDIUM] CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
It was reported [1],[2] that the fusermount tool was vulnerable to a race condition between mounting a user filesystem and updating mtab using the standard mount command. If a user were able to win the race, the real mount entry and the mtab entry would differ, making the fuse-mounted filesystem not unmountable by an unprivileged user. Crafted mtab entries can then be used to trick fusermount into believing that a certain part of the filesystem is a user-space filesystem, and will unmount what should be a privileged filesystem (as demonstrated by unmounting /proc).
According to the SUSE bug report [3], this would affect fuse versions before 2.8.2 or util-linu
Bugzilla
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
bugzilla·2010-06-17·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=591983
Please note: this issue af
Bugzilla
CVE-2010-0542 CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
bugzilla·2010-04-30·CVSS 6.8
CVE-2010-0542 [MEDIUM] CVE-2010-0542 CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
CVE-2010-0542 CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference
A NULL pointer dereference issue exists in the _WriteProlog function of the
texttops image filter. The return value from calloc is not checked. This
may lead to a NULL pointer dereference. Since the offset from the pointer
at which data is subsequently written is controlled by the user, this issue
may lead to application termination or arbitrary code execution.
Discussion:
Created attachment 410579
Proposed patch from Apple
---
Created attachment 412171
updated patch for 1.3.7
---
Acknowledgements:
Red Hat would like to thank the Apple Product Security team for responsibly reporting this issue. Upstream acknowledges regenrecht as the original reporter.
---
This is public now via t
http://cups.org/articles.php?L596http://cups.org/str.php?L3516http://cups.org/strfiles/3516/str3516.patchhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://securitytracker.com/id?1024121http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40943http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=587746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10365http://cups.org/articles.php?L596http://cups.org/str.php?L3516http://cups.org/strfiles/3516/str3516.patchhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://securitytracker.com/id?1024121http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40943http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=587746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10365
2010-06-21
Published