Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Cups | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Feb 21, 2008 |
| Debian | — | Upgrade cups | Jul 30, 2024 | Feb 21, 2008 |
| Gentoo Linux | — | Upgrade net-print/cups. | Oct 30, 2017 | Feb 21, 2008 |
| Oracle_linux | — | Upgrade cups-lpdUpgrade cups-libsUpgrade cups-develUpgrade cups | Oct 16, 2024 | Feb 21, 2008 |
| Suse | — | Upgrade cups-libs-64bitUpgrade cupsUpgrade cups-libs-32bitUpgrade cups-libsUpgrade suse-releaseUpgrade cups-libs-x86Upgrade cups-clientUpgrade cups-devel | Feb 17, 2015 | Feb 21, 2008 |
| Ubuntu | — | Upgrade cupsys | Nov 8, 2024 | Feb 21, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub