CVE-2008-5183

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/11/2008
Last modified:
09/04/2025

Description

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:* 1.3.9 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.5.6 (excluding)
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:* 10.5.6 (excluding)
cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools