CVE Database
/

CVE-2010-0302

Back to search

CVE-2010-0302

Published: Mar 5, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2010-06-15-1
vendor-advisory
x_refsource_APPLE
USN-906-1
vendor-advisory
x_refsource_UBUNTU
oval:org.mitre.oval:def:11216
vdb-entry
signature
x_refsource_OVAL
ADV-2010-1481
vdb-entry
x_refsource_VUPEN
1024124
vdb-entry
x_refsource_SECTRACK
GLSA-201207-10
vendor-advisory
x_refsource_GENTOO
FEDORA-2010-2743
vendor-advisory
x_refsource_FEDORA
40220
third-party-advisory
x_refsource_SECUNIA
MDVSA-2010:073
vendor-advisory
x_refsource_MANDRIVA
38510
vdb-entry
x_refsource_BID
38785
third-party-advisory
x_refsource_SECUNIA
RHSA-2010:0129
vendor-advisory
x_refsource_REDHAT
38979
third-party-advisory
x_refsource_SECUNIA
38927
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now