Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2432

Опубликовано: 03 мар. 2010
Источник: redhat

Описание

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.

Отчет

Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3, 4, or 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3cupsNot affected
Red Hat Enterprise Linux 4cupsAffected
Red Hat Enterprise Linux 5cupsAffected
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux Extended Update Support 4.8cupsAffected
Red Hat Enterprise Linux Extended Update Support 5.5cupsAffected

Показывать по

Дополнительная информация

Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=607211cups: DoS (infinite loop) via HTTP_UNAUTHORIZED responses STR #3518

Связанные уязвимости

ubuntu
больше 15 лет назад

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.

nvd
больше 15 лет назад

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.

debian
больше 15 лет назад

The cupsDoAuthentication function in auth.c in the client in CUPS befo ...

github
больше 3 лет назад

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.