CVE Database
/

CVE-2010-2941

Back to search

CVE-2010-2941

Published: Nov 5, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2010:234
vendor-advisory
x_refsource_MANDRIVA
ADV-2010-3042
vdb-entry
x_refsource_VUPEN
RHSA-2010:0811
vendor-advisory
x_refsource_REDHAT
RHSA-2010:0866
vendor-advisory
x_refsource_REDHAT
MDVSA-2010:232
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2010-17615
vendor-advisory
x_refsource_FEDORA
SUSE-SR:2010:023
vendor-advisory
x_refsource_SUSE
ADV-2010-2856
vdb-entry
x_refsource_VUPEN
DSA-2176
vendor-advisory
x_refsource_DEBIAN
1024662
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2010-11-10-1
vendor-advisory
x_refsource_APPLE
42867
third-party-advisory
x_refsource_SECUNIA
GLSA-201207-10
vendor-advisory
x_refsource_GENTOO
ADV-2011-0061
vdb-entry
x_refsource_VUPEN
FEDORA-2010-17641
vendor-advisory
x_refsource_FEDORA
ADV-2011-0535
vdb-entry
x_refsource_VUPEN
USN-1012-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2010-17627
vendor-advisory
x_refsource_FEDORA
MDVSA-2010:233
vendor-advisory
x_refsource_MANDRIVA
42287
third-party-advisory
x_refsource_SECUNIA
cups-cupsd-code-execution(62882)
vdb-entry
x_refsource_XF
43521
third-party-advisory
x_refsource_SECUNIA
SSA:2010-333-01
vendor-advisory
x_refsource_SLACKWARE
68951
vdb-entry
x_refsource_OSVDB
44530
vdb-entry
x_refsource_BID
ADV-2010-3088
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2010-2941 - Security Vulnerability | QwikSec