CVE: CVE-2009-0949

Export to Word

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

Threat-Mapped Scoring

Score: 1.5

Priority: P4 - Informational (Low)

EPSS

Score: 0.15376
Percentile: 0.94316

CVSS Scoring

CVSS v3.1 Score: 7.5

Severity: HIGH

Mapped CWE(s)

Affected Products

← Back to Home