Improper Memory Allocation Vulnerability in CUPS by Apple
CVE-2010-2941

9.8CRITICAL

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
5 November 2010

What is CVE-2010-2941?

The CUPS software, specifically the ipp.c component within cupsd, exhibits a vulnerability due to improper memory allocation for attribute values that contain invalid string data types. This flaw enables remote attackers to potentially crash the application or create a denial of service situation through specially crafted IPP requests. The vulnerability may also allow attackers to execute arbitrary code, putting systems at risk, making it essential for organizations to update to the latest version to mitigate the risk.

References

EPSS Score

27% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.