vendor:
CUPS
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: CUPS
Affected Version From: 1.1.17
Affected Version To: 1.1.19
Patch Exists: YES
Related CWE: CVE-2003-0037
CPE: a:apple:cups
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: BSD
2003
CUPS Malformed HTTP Headers Denial of Service Vulnerability
A vulnerability has been reported for CUPS that if exploited may result in a DoS or the execute of code on affected systems. An attacker can exploit this vulnerability by connecting to a vulnerable system and issuing malformed HTTP headers with a negative value for some fields. When the cupsd service receives this request, it will crash.
Mitigation:
Update to the latest version of CUPS