7.5
CVE-2010-0302
- EPSS 2.58%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:15:53
- Erkennungen
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ macOS X Server Version < 10.5.8
Apple ≫ macOS X Server Version >= 10.6.0 < 10.6.4
Fedoraproject ≫ Fedora Version 11
Canonical ≫ Ubuntu Linux Version 6.06
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 8.10
Canonical ≫ Ubuntu Linux Version 9.04
Canonical ≫ Ubuntu Linux Version 9.10
Redhat ≫ Enterprise Linux Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Eus Version 5.4
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.58% | 0.832 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html
http://secunia.com/advisories/40220
http://support.apple.com/kb/HT4188
http://www.vupen.com/english/advisories/2010/1481
http://www.mandriva.com/security/advisories?name=MDVSA-2010:073
http://security.gentoo.org/glsa/glsa-201207-10.xml
http://www.ubuntu.com/usn/USN-906-1
http://cups.org/articles.php?L596
http://cups.org/str.php?L3490
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037174.html
http://secunia.com/advisories/38785
http://secunia.com/advisories/38927
http://secunia.com/advisories/38979
http://www.securityfocus.com/bid/38510
http://www.securitytracker.com/id?1024124
https://bugzilla.redhat.com/show_bug.cgi?id=557775
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11216
https://rhn.redhat.com/errata/RHSA-2010-0129.html