Authorization Handling Flaw in CUPS Affects Users
CVE-2010-2432

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
22 June 2010

Summary

The cupsDoAuthentication function in CUPS prior to version 1.4.4 contains a flaw related to authorization management when the HAVE_GSSAPI directive is omitted. This vulnerability allows remote CUPS servers to exploit the denial of service condition by issuing HTTP_UNAUTHORIZED responses, potentially leading to an infinite loop situation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.