CVE
- Id
- 38384
- CVE No.
- CVE-2009-0949
- Status
- Candidate
- Description
- The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
- Phase
- Assigned (20090318)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 418875 | 38384 | CVE-2009-0949 | BUGTRAQ:20090602 CORE-2009-0420 - Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability | View |
| 418876 | 38384 | CVE-2009-0949 | URL:http://www.securityfocus.com/archive/1/archive/1/504032/100/0/threaded | View |
| 418877 | 38384 | CVE-2009-0949 | MISC:http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability | View |
| 418878 | 38384 | CVE-2009-0949 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=500972 | View |
| 418879 | 38384 | CVE-2009-0949 | CONFIRM:http://support.apple.com/kb/HT3865 | View |
| 418880 | 38384 | CVE-2009-0949 | APPLE:APPLE-SA-2009-09-10-2 | View |
| 418881 | 38384 | CVE-2009-0949 | URL:http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html | View |
| 418882 | 38384 | CVE-2009-0949 | DEBIAN:DSA-1811 | View |
| 418883 | 38384 | CVE-2009-0949 | URL:http://www.debian.org/security/2009/dsa-1811 | View |
| 418884 | 38384 | CVE-2009-0949 | REDHAT:RHSA-2009:1082 | View |
| 418885 | 38384 | CVE-2009-0949 | URL:http://www.redhat.com/support/errata/RHSA-2009-1082.html | View |
| 418886 | 38384 | CVE-2009-0949 | REDHAT:RHSA-2009:1083 | View |
| 418887 | 38384 | CVE-2009-0949 | URL:http://www.redhat.com/support/errata/RHSA-2009-1083.html | View |
| 418888 | 38384 | CVE-2009-0949 | SUSE:SUSE-SR:2009:012 | View |
| 418889 | 38384 | CVE-2009-0949 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html | View |
| 418890 | 38384 | CVE-2009-0949 | UBUNTU:USN-780-1 | View |
| 418891 | 38384 | CVE-2009-0949 | URL:http://www.ubuntu.com/usn/USN-780-1 | View |
| 418892 | 38384 | CVE-2009-0949 | BID:35169 | View |
| 418893 | 38384 | CVE-2009-0949 | URL:http://www.securityfocus.com/bid/35169 | View |
| 418894 | 38384 | CVE-2009-0949 | OVAL:oval:org.mitre.oval:def:9631 | View |
| 418895 | 38384 | CVE-2009-0949 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9631 | View |
| 418896 | 38384 | CVE-2009-0949 | SECTRACK:1022321 | View |
| 418897 | 38384 | CVE-2009-0949 | URL:http://securitytracker.com/id?1022321 | View |
| 418898 | 38384 | CVE-2009-0949 | SECUNIA:35322 | View |
| 418899 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/35322 | View |
| 418900 | 38384 | CVE-2009-0949 | SECUNIA:35328 | View |
| 418901 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/35328 | View |
| 418902 | 38384 | CVE-2009-0949 | SECUNIA:35340 | View |
| 418903 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/35340 | View |
| 418904 | 38384 | CVE-2009-0949 | SECUNIA:35342 | View |
| 418905 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/35342 | View |
| 418906 | 38384 | CVE-2009-0949 | SECUNIA:35685 | View |
| 418907 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/35685 | View |
| 418908 | 38384 | CVE-2009-0949 | SECUNIA:36701 | View |
| 418909 | 38384 | CVE-2009-0949 | URL:http://secunia.com/advisories/36701 | View |
| 418910 | 38384 | CVE-2009-0949 | XF:apple-cups-ipptag-dos(50926) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40717 | JVNDB-2009-001723 | Apple QuickTime における PICT 画像の処理に関する任意のコードを実行される脆弱性 | Apple QuickTime には、PICT 画像の処理に不備があることにより、任意のコードを実行される、あるいはサービス運用妨害 (DoS) 状態にされる脆弱性が存在します。 | CVE-2009-0953 | 38384 | 9.3 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001723.html | View |