CUPS Denial of Service Attack Vulnerability

Michael Sweet <[email protected]> Tue, 27 May 2003 13:43:14 -0400
Newsgroups gmane.comp.printing.cups.announce
Organization Easy Software Products
Message-ID <[email protected]>
A denial of service attack vulnerability, STR #75, was discovered and 
reported by Red Hat which allows a malicious user to block the CUPS 
scheduler while servicing a request, effectively preventing other users 
from accessing the scheduler. This vulnerability exists for both local 
and remote accesses to all CUPS versions up to and including 1.1.19rc3.

A patch for CUPS 1.1.18 is available on the STR page. CUPS 1.1.19rc4 and 
higher do not contain this vulnerability and do not require any 
additional patches.