4.3
CVSSv2

CVE-2010-0302

Published: 05/03/2010 Updated: 03/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS prior to 1.4.4, when kqueue or epoll is used, allows remote malicious users to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x server

apple mac os x

apple cups

fedoraproject fedora 11

canonical ubuntu linux 9.04

canonical ubuntu linux 8.10

canonical ubuntu linux 9.10

canonical ubuntu linux 8.04

canonical ubuntu linux 6.06

redhat enterprise linux server 5.0

redhat enterprise linux workstation 5.0

redhat enterprise linux 5.0

redhat enterprise linux desktop 5.0

redhat enterprise linux eus 5.4

Vendor Advisories

Synopsis Moderate: cups security update Type/Severity Security Advisory: Moderate Topic Updated cups packages that fix one security issue are now available for RedHat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Description ...
Debian Bug report logs - #572940 CVE-2010-0302: Incomplete security fix Package: cups; Maintainer for cups is Debian Printing Team <debian-printing@listsdebianorg>; Source for cups is src:cups (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 7 Mar 2010 19:00:01 UTC Severity: impor ...
It was discovered that the CUPS scheduler did not properly handle certain network operations A remote attacker could exploit this flaw and cause the CUPS server to crash, resulting in a denial of service This issue only affected Ubuntu 804 LTS, 810, 904 and 910 (CVE-2009-3553, CVE-2010-0302) ...