CVE: CVE-2010-2941

Export to Word

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

Threat-Mapped Scoring

Score: 1.9

Priority: P3 - Important (Medium)

EPSS

Score: 0.27685
Percentile: 0.96222

CVSS Scoring

CVSS v3.1 Score: 9.8

Severity: CRITICAL

Mapped CWE(s)

Affected Products

← Back to Home