CVE-2010-0542
Summary
| CVE | CVE-2010-0542 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-21 16:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Cups | 1.1 | All | All | All |
| Application | Apple | Cups | 1.1.1 | All | All | All |
| Application | Apple | Cups | 1.1.10 | All | All | All |
| Application | Apple | Cups | 1.1.10-1 | All | All | All |
| Application | Apple | Cups | 1.1.11 | All | All | All |
| Application | Apple | Cups | 1.1.12 | All | All | All |
| Application | Apple | Cups | 1.1.13 | All | All | All |
| Application | Apple | Cups | 1.1.14 | All | All | All |
| Application | Apple | Cups | 1.1.15 | All | All | All |
| Application | Apple | Cups | 1.1.16 | All | All | All |
| Application | Apple | Cups | 1.1.17 | All | All | All |
| Application | Apple | Cups | 1.1.18 | All | All | All |
| Application | Apple | Cups | 1.1.19 | All | All | All |
| Application | Apple | Cups | 1.1.19 | rc1 | All | All |
| Application | Apple | Cups | 1.1.19 | rc2 | All | All |
| Application | Apple | Cups | 1.1.19 | rc3 | All | All |
| Application | Apple | Cups | 1.1.19 | rc4 | All | All |
| Application | Apple | Cups | 1.1.19 | rc5 | All | All |
| Application | Apple | Cups | 1.1.2 | All | All | All |
| Application | Apple | Cups | 1.1.20 | All | All | All |
| Application | Apple | Cups | 1.1.20 | rc1 | All | All |
| Application | Apple | Cups | 1.1.20 | rc2 | All | All |
| Application | Apple | Cups | 1.1.20 | rc3 | All | All |
| Application | Apple | Cups | 1.1.20 | rc4 | All | All |
| Application | Apple | Cups | 1.1.20 | rc5 | All | All |
| Application | Apple | Cups | 1.1.20 | rc6 | All | All |
| Application | Apple | Cups | 1.1.21 | All | All | All |
| Application | Apple | Cups | 1.1.21 | rc1 | All | All |
| Application | Apple | Cups | 1.1.21 | rc2 | All | All |
| Application | Apple | Cups | 1.1.22 | All | All | All |
| Application | Apple | Cups | 1.1.22 | rc1 | All | All |
| Application | Apple | Cups | 1.1.22 | rc2 | All | All |
| Application | Apple | Cups | 1.1.23 | All | All | All |
| Application | Apple | Cups | 1.1.23 | rc1 | All | All |
| Application | Apple | Cups | 1.1.3 | All | All | All |
| Application | Apple | Cups | 1.1.4 | All | All | All |
| Application | Apple | Cups | 1.1.5 | All | All | All |
| Application | Apple | Cups | 1.1.5-1 | All | All | All |
| Application | Apple | Cups | 1.1.5-2 | All | All | All |
| Application | Apple | Cups | 1.1.6 | All | All | All |
| Application | Apple | Cups | 1.1.6-1 | All | All | All |
| Application | Apple | Cups | 1.1.6-2 | All | All | All |
| Application | Apple | Cups | 1.1.6-3 | All | All | All |
| Application | Apple | Cups | 1.1.7 | All | All | All |
| Application | Apple | Cups | 1.1.8 | All | All | All |
| Application | Apple | Cups | 1.1.9 | All | All | All |
| Application | Apple | Cups | 1.1.9-1 | All | All | All |
| Application | Apple | Cups | 1.2 | b1 | All | All |
| Application | Apple | Cups | 1.2 | b2 | All | All |
| Application | Apple | Cups | 1.2 | rc1 | All | All |
| Application | Apple | Cups | 1.2 | rc2 | All | All |
| Application | Apple | Cups | 1.2 | rc3 | All | All |
| Application | Apple | Cups | 1.2.0 | All | All | All |
| Application | Apple | Cups | 1.2.1 | All | All | All |
| Application | Apple | Cups | 1.2.10 | All | All | All |
| Application | Apple | Cups | 1.2.11 | All | All | All |
| Application | Apple | Cups | 1.2.12 | All | All | All |
| Application | Apple | Cups | 1.2.2 | All | All | All |
| Application | Apple | Cups | 1.2.3 | All | All | All |
| Application | Apple | Cups | 1.2.4 | All | All | All |
| Application | Apple | Cups | 1.2.5 | All | All | All |
| Application | Apple | Cups | 1.2.6 | All | All | All |
| Application | Apple | Cups | 1.2.7 | All | All | All |
| Application | Apple | Cups | 1.2.8 | All | All | All |
| Application | Apple | Cups | 1.2.9 | All | All | All |
| Application | Apple | Cups | 1.3 | b1 | All | All |
| Application | Apple | Cups | 1.3 | rc1 | All | All |
| Application | Apple | Cups | 1.3 | rc2 | All | All |
| Application | Apple | Cups | 1.3.0 | All | All | All |
| Application | Apple | Cups | 1.3.1 | All | All | All |
| Application | Apple | Cups | 1.3.10 | All | All | All |
| Application | Apple | Cups | 1.3.11 | All | All | All |
| Application | Apple | Cups | 1.3.2 | All | All | All |
| Application | Apple | Cups | 1.3.3 | All | All | All |
| Application | Apple | Cups | 1.3.4 | All | All | All |
| Application | Apple | Cups | 1.3.5 | All | All | All |
| Application | Apple | Cups | 1.3.6 | All | All | All |
| Application | Apple | Cups | 1.3.7 | All | All | All |
| Application | Apple | Cups | 1.3.8 | All | All | All |
| Application | Apple | Cups | 1.3.9 | All | All | All |
| Application | Apple | Cups | 1.4.0 | All | All | All |
| Application | Apple | Cups | 1.4.1 | All | All | All |
| Application | Apple | Cups | 1.4.2 | All | All | All |
| Application | Apple | Cups | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - CUPS Null Pointer Dereference in 'texttops' Filter Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Debian update for cups - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 587746 – (CVE-2010-0542) CVE-2010-0542 CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Article #596: CUPS 1.4.4 - Documentation - CUPS | af854a3a-2127-422b-91ae-364da2661108 | cups.org | Patch |
| Support / Security / Advisories / / MDVSA-2010:232 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-2176-1 cups | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Gentoo Linux Documentation -- CUPS: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:023 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support / Security / Advisories / / MDVSA-2010:234 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Page Has Moved - CUPS.org | af854a3a-2127-422b-91ae-364da2661108 | cups.org | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Missing malloc checks in texttops · Issue #3516 · apple/cups · GitHub | af854a3a-2127-422b-91ae-364da2661108 | cups.org | |
| CUPS 'texttops' Filter NULL-pointer Dereference Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.