Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2010-0866

Опубликовано: 10 фев. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2010-0866: cups security update (IMPORTANT)

[1:1.4.2-35:.1]

  • Applied patch to fix cupsd memory corruption vulnerability (CVE-2010-2941, STR #3648, bug #624438).

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

cups

1.4.2-35.el6_0.1

cups-devel

1.4.2-35.el6_0.1

cups-libs

1.4.2-35.el6_0.1

cups-lpd

1.4.2-35.el6_0.1

cups-php

1.4.2-35.el6_0.1

Oracle Linux i686

cups

1.4.2-35.el6_0.1

cups-devel

1.4.2-35.el6_0.1

cups-libs

1.4.2-35.el6_0.1

cups-lpd

1.4.2-35.el6_0.1

cups-php

1.4.2-35.el6_0.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 14 лет назад

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

redhat
больше 14 лет назад

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

CVSS3: 9.8
nvd
больше 14 лет назад

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

CVSS3: 9.8
debian
больше 14 лет назад

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate me ...

CVSS3: 9.8
github
около 3 лет назад

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.