REDHAT-BUG-2393078: Null Pointer Dereference
Null Pointer Dereference vulnerability in the ippreadio() function of the CUPS printing system. The flaw is caused by unsafe deserialization and improper validation of crafted printer attribute responses. When ippValidateAttributes() processes such responses, a null pointer dereference occurs, leading to application crash. This issue can be exploited remotely within the local subnet in default configurations, and in some cases over the network if IPP services are exposed. Exploitation requires no authentication or user interaction, allowing attackers to disrupt availability of printing services on affected systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2393078?
The severity of REDHAT-BUG-2393078 is considered high due to the potential for a null pointer dereference that can lead to application crashes.
How do I fix REDHAT-BUG-2393078?
To fix REDHAT-BUG-2393078, update your CUPS system to the latest version that addresses the vulnerability.
What is the impact of REDHAT-BUG-2393078?
The impact of REDHAT-BUG-2393078 includes potential denial of service due to crashes when handling malicious printer attribute responses.
Who is affected by REDHAT-BUG-2393078?
Users of Apple CUPS are notably affected by the REDHAT-BUG-2393078 vulnerability.
Is there a workaround for REDHAT-BUG-2393078?
There are no recommended workarounds for REDHAT-BUG-2393078; applying the latest updates is the best mitigation strategy.