CVE-2010-2941
published 2010-11-05CVE-2010-2941: ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.47%
93.0th percentile
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.4 | — |
| apple | cups | >= 0 < 1.4.4-7 | 1.4.4-7 |
| apple | cups | >= 0 < 1.4.4-7 | 1.4.4-7 |
| apple | cups | >= 0 < 1.4.4-7 | 1.4.4-7 |
| apple | cups | >= 0 < 1.4.4-7 | 1.4.4-7 |
| apple | mac_os_x | < 10.5.8 | 10.5.8 |
| apple | mac_os_x | 10.6.0 – 10.6.4 | — |
| apple | mac_os_x_server | < 10.5.8 | 10.5.8 |
| apple | mac_os_x_server | 10.6.0 – 10.6.4 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < cups 1.4.4-7 (bookworm) | cups 1.4.4-7 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pp56-6c5p-hfmv: ipp
ghsa_unreviewed·2022-05-17
CVE-2010-2941 [HIGH] CWE-416 GHSA-pp56-6c5p-hfmv: ipp
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
OSV
CVE-2010-2941: ipp
osv·2010-11-05·CVSS 9.8
CVE-2010-2941 [CRITICAL] CVE-2010-2941: ipp
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2010-11-04
CVE-2010-2941 CUPS vulnerability
Title: CUPS vulnerability
Emmanuel Bouillon discovered that CUPS did not properly handle certain
Internet Printing Protocol (IPP) packets. A remote attacker could use this
flaw to cause a denial of service or possibly execute arbitrary code. In
the default installation in Ubuntu 8.04 LTS and later, attackers would be
isolated by the CUPS AppArmor profile.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: cupsd memory corruption vulnerability
vendor_redhat·2010-10-28·CVSS 9.8
CVE-2010-2941 [CRITICAL] cups: cupsd memory corruption vulnerability
cups: cupsd memory corruption vulnerability
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
Package: cups (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-2941: cups - ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for a...
vendor_debian·2010·CVSS 9.8
CVE-2010-2941 [CRITICAL] CVE-2010-2941: cups - ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for a...
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
Scope: local
bookworm: resolved (fixed in 1.4.4-7)
bullseye: resolved (fixed in 1.4.4-7)
forky: resolved (fixed in 1.4.4-7)
sid: resolved (fixed in 1.4.4-7)
trixie: resolved (fixed in 1.4.4-7)
No detection rules found.
Bugzilla
CVE-2010-2941 cups: cupsd memory corruption vulnerability [fedora-all]
bugzilla·2010-11-11·CVSS 9.8
CVE-2010-2941 [CRITICAL] CVE-2010-2941 cups: cupsd memory corruption vulnerability [fedora-all]
CVE-2010-2941 cups: cupsd memory corruption vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=624438
Please note: this issue affects multiple sup
Bugzilla
CVE-2010-2941 cups: cupsd memory corruption vulnerability
bugzilla·2010-08-16·CVSS 9.8
CVE-2010-2941 [CRITICAL] CVE-2010-2941 cups: cupsd memory corruption vulnerability
CVE-2010-2941 cups: cupsd memory corruption vulnerability
Emmanuel Bouillon reported a memory corruption flaw in CUPS daemon. A specially-crafted IPP request can cause daemon to crash or, possibly, execute arbitrary code.
Acknowledgements:
Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for reporting this issue.
Discussion:
The problem is a mismatch between different memory allocators.
In the IPP protocol, an attribute can have multiple values, and each value is typed. In the CUPS data model for this, all values for a given attribute must have the same (or a compatible) type.
String types have values allocated with the StrAlloc allocator, a reference-counting string pool.
'Unknown' types use malloc.
By giving the first value for an attribute a value tag of 56, whic
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050977.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051277.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051301.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2010-0811.htmlhttp://secunia.com/advisories/42287http://secunia.com/advisories/42867http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://securitytracker.com/id?1024662http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.468323http://support.apple.com/kb/HT4435http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:233http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.osvdb.org/68951http://www.redhat.com/support/errata/RHSA-2010-0866.htmlhttp://www.securityfocus.com/bid/44530http://www.ubuntu.com/usn/USN-1012-1http://www.vupen.com/english/advisories/2010/2856http://www.vupen.com/english/advisories/2010/3042http://www.vupen.com/english/advisories/2010/3088http://www.vupen.com/english/advisories/2011/0061http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=624438https://exchange.xforce.ibmcloud.com/vulnerabilities/62882http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050977.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051277.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051301.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2010-0811.htmlhttp://secunia.com/advisories/42287http://secunia.com/advisories/42867http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://securitytracker.com/id?1024662http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.468323http://support.apple.com/kb/HT4435http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:233http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.osvdb.org/68951http://www.redhat.com/support/errata/RHSA-2010-0866.htmlhttp://www.securityfocus.com/bid/44530http://www.ubuntu.com/usn/USN-1012-1http://www.vupen.com/english/advisories/2010/2856http://www.vupen.com/english/advisories/2010/3042http://www.vupen.com/english/advisories/2010/3088http://www.vupen.com/english/advisories/2011/0061http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=624438https://exchange.xforce.ibmcloud.com/vulnerabilities/62882
2010-11-05
Published