The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Cups | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Apr 24, 2009 |
| Debian | — | Upgrade cups | Jul 30, 2024 | Apr 24, 2009 |
| Freebsd | — | Upgrade cups-base | Dec 10, 2025 | May 7, 2009 |
| Gentoo Linux | — | Upgrade net-print/cups. | Oct 30, 2017 | Apr 24, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 16, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub