CUPS Denial of Service Attack Vulnerability
Michael Sweet <[email protected]> Tue, 27 May 2003 13:43:14 -0400
| Newsgroups | gmane.comp.printing.cups.announce |
|---|---|
| Organization | Easy Software Products |
| Message-ID | <[email protected]> |
A denial of service attack vulnerability, STR #75, was discovered and reported by Red Hat which allows a malicious user to block the CUPS scheduler while servicing a request, effectively preventing other users from accessing the scheduler. This vulnerability exists for both local and remote accesses to all CUPS versions up to and including 1.1.19rc3. A patch for CUPS 1.1.18 is available on the STR page. CUPS 1.1.19rc4 and higher do not contain this vulnerability and do not require any additional patches.