The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a pointer use-after-delete flaw.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cups | Apple | 1.1.17 (including) | 1.1.17 (including) |
| Cups | Apple | 1.1.22 (including) | 1.1.22 (including) |
| Red Hat Enterprise Linux 3 | RedHat | cups-1:1.1.17-13.3.62 | * |
| Red Hat Enterprise Linux 4 | RedHat | cups-1:1.1.22-0.rc1.9.32.el4_8.3 | * |
| Cups | Ubuntu | upstream | * |
| Cupsys | Ubuntu | upstream | * |