Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 273911 (CVE-2009-0949) - <net-print/cups-1.3.10-r1 IPP DOS (CVE-2009-0949)
Summary: <net-print/cups-1.3.10-r1 IPP DOS (CVE-2009-0949)
Status: RESOLVED FIXED
Alias: CVE-2009-0949
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-06-12 20:21 UTC by Stefan Behte (RETIRED)
Modified: 2009-07-15 15:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-06-12 20:21:35 UTC
CVE-2009-0949 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0949):
  The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10
  does not properly initialize memory for IPP request packets, which
  allows remote attackers to cause a denial of service (NULL pointer
  dereference and daemon crash) via a scheduler request with two
  consecutive IPP_TAG_UNSUPPORTED tags.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-12 20:24:44 UTC
We seem to already have the patch (https://bugzilla.redhat.com/attachment.cgi?id=344106), but no bug for this as far as I can see, and a vulnerable version is still in tree.
Printing: is it ok to remove it? If so, please do it.
Comment 2 Timo Gurr (RETIRED) gentoo-dev 2009-07-08 22:43:40 UTC
Yes thanks, all versions <net-print/cups-1.3.10-r1 are gone now.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-07-15 15:41:02 UTC
A glsa for all affected versions has been issued, 200904-20. It did not specifically cover this, but vulnerabilities with worse impact. [noglsa] for this issue thus.