First published: Thu Dec 26 2002(Updated: )
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CUPS (Common UNIX Printing System) | =1.1.10 | |
CUPS (Common UNIX Printing System) | =1.1.7 | |
CUPS (Common UNIX Printing System) | =1.0.4_8 | |
CUPS (Common UNIX Printing System) | =1.1.13 | |
CUPS (Common UNIX Printing System) | =1.1.17 | |
CUPS (Common UNIX Printing System) | =1.1.4_3 | |
CUPS (Common UNIX Printing System) | =1.1.4 | |
CUPS (Common UNIX Printing System) | =1.1.4_5 | |
CUPS (Common UNIX Printing System) | =1.1.1 | |
CUPS (Common UNIX Printing System) | =1.0.4 | |
CUPS (Common UNIX Printing System) | =1.1.14 | |
CUPS (Common UNIX Printing System) | =1.1.4_2 | |
CUPS (Common UNIX Printing System) | =1.1.6 | |
Apple iOS and macOS | =10.2.2 | |
Apple iOS and macOS | =10.2 | |
CUPS | >=1.1.14<=1.1.17 | |
Debian | =2.2 | |
Debian | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1372 is classified as a denial of service vulnerability due to its potential for resource exhaustion.
To remediate CVE-2002-1372, update to a version of CUPS that is higher than 1.1.17.
CVE-2002-1372 affects users of CUPS versions 1.1.14 through 1.1.17 and various versions of macOS and Debian Linux.
The attack vector for CVE-2002-1372 is remote, allowing attackers to trigger resource exhaustion on vulnerable systems.
Exploitation of CVE-2002-1372 may result in service disruption and unavailability of printing services.