CVE-2007-4045: Medium severity Apple CUPS vulnerability
Description of problem:
SUSE-SR:2007:014 (see URL field) reads:
- cups denial of service regression fix
CUPS packages were released to fix another denial of service problem introduced by the previous Denial of Service Fix for CVE-2007-0720, which was incomplete.
Version-Release number of selected component (if applicable):
CVE-2007-4045 Affects: RHEL4 CVE-2007-4045 Affects: RHEL5 CVE-2007-4045 Affects: FC6 CVE-2007-4045 Affects: FC7
Other sources
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2007-4045?
CVE-2007-4045 is classified as a denial of service vulnerability.
How do I fix CVE-2007-4045?
To fix CVE-2007-4045, update the CUPS package to a version that is not affected by this vulnerability.
What is the impact of CVE-2007-4045 on systems?
CVE-2007-4045 can cause various denial of service issues that disrupt the CUPS service.
Which versions of CUPS are affected by CVE-2007-4045?
Versions of CUPS prior to 1.2.0 and certain versions in RedHat and SUSE Linux distributions are affected by CVE-2007-4045.
Who should be concerned about CVE-2007-4045?
Administrators using affected versions of the CUPS service in Linux distributions should take this vulnerability seriously.