Secunia Logo
 
CVE Reference: CVE-2005-2874
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2874

Description:
The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

CVE Status:
Candidate

References:

ST
  1012811

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-772.html

MISC

FEDORA
  http://lwn.net/Alerts/152835/

CONFIRM
  http://www.cups.org/relnotes.php#010123
  http://www.cups.org/str.php?L1042+P0+S-1+C0+I0+E0+Q1042


Return to the previous page.