CVE-2010-2432
published 2010-06-22CVE-2010-2432: The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.10%
79.7th percentile
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.3 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hv7x-wq9f-458x: The cupsDoAuthentication function in auth
ghsa_unreviewed·2022-05-17
CVE-2010-2432 [MEDIUM] GHSA-hv7x-wq9f-458x: The cupsDoAuthentication function in auth
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
OSV
CVE-2010-2432: The cupsDoAuthentication function in auth
osv·2010-06-22·CVSS 5.0
CVE-2010-2432 [MEDIUM] CVE-2010-2432: The cupsDoAuthentication function in auth
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
Red Hat
cups: DoS (infinite loop) via HTTP_UNAUTHORIZED responses STR #3518
vendor_redhat·2010-03-03·CVSS 5.0
CVE-2010-2432 [MEDIUM] CWE-835 cups: DoS (infinite loop) via HTTP_UNAUTHORIZED responses STR #3518
cups: DoS (infinite loop) via HTTP_UNAUTHORIZED responses STR #3518
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
Statement: Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Package: cups (Red Hat Enterprise Linux 4) - Affected
Package: cups (Red Hat Enterprise Linux 5) - Affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2432: cups - The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, ...
vendor_debian·2010·CVSS 5.0
CVE-2010-2432 [MEDIUM] CVE-2010-2432: cups - The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, ...
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
No detection rules found.
No public exploits indexed.
http://cups.org/articles.php?L596http://cups.org/str.php?L3518http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2011:146http://www.vupen.com/english/advisories/2011/0535http://cups.org/articles.php?L596http://cups.org/str.php?L3518http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2011:146http://www.vupen.com/english/advisories/2011/0535
2010-06-22
Published