First published: Tue Jun 22 2010(Updated: )
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CUPS | =1.1.20 | |
CUPS | =1.1.5-2 | |
CUPS | =1.3.9 | |
CUPS | =1.1.14 | |
CUPS | =1.3-rc2 | |
CUPS | =1.1.6-1 | |
CUPS | =1.1.18 | |
CUPS | =1.1.12 | |
CUPS | <=1.4.3 | |
CUPS | =1.3.11 | |
CUPS | =1.1.5-1 | |
CUPS | =1.3.3 | |
CUPS | =1.1.22 | |
CUPS | =1.2.0 | |
CUPS | =1.1.16 | |
CUPS | =1.4.1 | |
CUPS | =1.3.1 | |
CUPS | =1.1.23-rc1 | |
CUPS | =1.1.20-rc1 | |
CUPS | =1.1.15 | |
CUPS | =1.1.17 | |
CUPS | =1.1.20-rc6 | |
CUPS | =1.2.4 | |
CUPS | =1.1.19-rc1 | |
CUPS | =1.3.2 | |
CUPS | =1.1.22-rc1 | |
CUPS | =1.1.7 | |
CUPS | =1.2-rc2 | |
CUPS | =1.1.6-2 | |
CUPS | =1.3-b1 | |
CUPS | =1.1.3 | |
CUPS | =1.2.3 | |
CUPS | =1.1.21 | |
CUPS | =1.4.0 | |
CUPS | =1.2.9 | |
CUPS | =1.2.10 | |
CUPS | =1.1.4 | |
CUPS | =1.1.23 | |
CUPS | =1.2.6 | |
CUPS | =1.2-b1 | |
CUPS | =1.3.8 | |
CUPS | =1.1.20-rc4 | |
CUPS | =1.1.19 | |
CUPS | =1.1 | |
CUPS | =1.3.4 | |
CUPS | =1.1.8 | |
CUPS | =1.1.5 | |
CUPS | =1.2.1 | |
CUPS | =1.2-rc3 | |
CUPS | =1.1.2 | |
CUPS | =1.3.10 | |
CUPS | =1.1.13 | |
CUPS | =1.1.19-rc4 | |
CUPS | =1.1.9-1 | |
CUPS | =1.2.12 | |
CUPS | =1.1.21-rc2 | |
CUPS | =1.2-b2 | |
CUPS | =1.2.7 | |
CUPS | =1.1.6-3 | |
CUPS | =1.1.20-rc5 | |
CUPS | =1.1.9 | |
CUPS | =1.3.7 | |
CUPS | =1.1.19-rc5 | |
CUPS | =1.2-rc1 | |
CUPS | =1.1.1 | |
CUPS | =1.2.8 | |
CUPS | =1.2.2 | |
CUPS | =1.4.2 | |
CUPS | =1.1.10 | |
CUPS | =1.2.11 | |
CUPS | =1.1.22-rc2 | |
CUPS | =1.1.21-rc1 | |
CUPS | =1.3-rc1 | |
CUPS | =1.1.11 | |
CUPS | =1.1.19-rc3 | |
CUPS | =1.1.6 | |
CUPS | =1.1.10-1 | |
CUPS | =1.3.0 | |
CUPS | =1.3.5 | |
CUPS | =1.3.6 | |
CUPS | =1.1.20-rc2 | |
CUPS | =1.1.20-rc3 | |
CUPS | =1.2.5 | |
CUPS | =1.1.19-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2432 is classified as a denial of service vulnerability that can lead to an infinite loop in affected versions of CUPS.
To fix CVE-2010-2432, upgrade your CUPS installation to version 1.4.4 or later.
CVE-2010-2432 affects CUPS versions prior to 1.4.4, including specific earlier versions such as 1.1.20, 1.1.18, 1.3.9, and others.
The vulnerability is found in the cupsDoAuthentication function within the auth.c file of CUPS.
Yes, CVE-2010-2432 can be exploited remotely by sending HTTP_UNAUTHORIZED responses that trigger the denial of service condition.