OSVDB ID: 9995

Title: CUPS Empty UDP Datagram DoS

Info

Disclosure

Sep 16, 2004

Discovery

Aug 21, 2004

Dates

Exploit

Aug 21, 2004

Solution

Unknown

Description

CUPS contains a flaw that may allow a remote denial of service. The issue is triggered when an empty UDP packet is sent to port 631 and will result in loss of availability for the cupsd.

Classification

Location: Remote/Network Access Required
Attack Type: Denial of Service
Impact: Loss of Availability
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.1.21rc2 or higher, as it has been reported to fix this vulnerability. Additionally, a patch has been provided to mitigate this issue.

Products

Easy Software Products

CUPS

1.1.x
1.0.x

References

Credit

  • Alvaro Martinez Echevarria -


Direct URL: http://osvdb.org/36218