cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cups | Apple | * | 1.3.9 (including) |
Cups | Ubuntu | intrepid | * |
Cupsys | Ubuntu | gutsy | * |
Cupsys | Ubuntu | hardy | * |
Red Hat Enterprise Linux 5 | RedHat | cups-1:1.2.4-11.18.el5_2.3 | * |