CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
BID:26524
Info
CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
| Bugtraq ID: | 26524 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-4045 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2007 12:00AM |
| Updated: | Jun 16 2008 10:12PM |
| Credit: | This issue was disclosed in a SUSE Linux security advisory. |
| Vulnerable: |
Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 TurboLinux Personal TurboLinux Multimedia Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 3.0 x64 Turbolinux Appliance Server 3.0 Turbolinux Appliance Server 2.0 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server 9-SP3 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 10.SP1 S.u.S.E. Linux Enterprise Server 10 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server S.u.S.E. Linux 1.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora Core7 Red Hat Fedora Core6 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Easy Software Products CUPS 1.3.3 Easy Software Products CUPS 1.2.12 Easy Software Products CUPS 1.2.10 Easy Software Products CUPS 1.2.9 Easy Software Products CUPS 1.2.4 Easy Software Products CUPS 1.1.23 rc1 Easy Software Products CUPS 1.1.23 Easy Software Products CUPS 1.1.22 rc1 Easy Software Products CUPS 1.1.22 Easy Software Products CUPS 1.1.21 Easy Software Products CUPS 1.1.20 Easy Software Products CUPS 1.1.19 rc5 Easy Software Products CUPS 1.1.19 Easy Software Products CUPS 1.1.18 Easy Software Products CUPS 1.1.17 Easy Software Products CUPS 1.1.16 Easy Software Products CUPS 1.1.15 Easy Software Products CUPS 1.1.14 Easy Software Products CUPS 1.1.13 Easy Software Products CUPS 1.1.12 Easy Software Products CUPS 1.1.10 Easy Software Products CUPS 1.1.7 Easy Software Products CUPS 1.1.6 Easy Software Products CUPS 1.1.4 -5 Easy Software Products CUPS 1.1.4 -3 Easy Software Products CUPS 1.1.4 -2 Easy Software Products CUPS 1.1.4 Easy Software Products CUPS 1.1.1 Easy Software Products CUPS 1.0.4 -8 Easy Software Products CUPS 1.0.4 DrPhibez and Nitro187 Guild FTPD 1.1.19 rc5 Avaya Aura Application Enablement Services 3.0 |
| Not Vulnerable: | |
Discussion
CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
CUPS is prone to an unspecified remote denial-of-service vulnerability when handling SSL connection requests.
Successfully exploiting this issue allows remote attackers to cause the affected service to crash, denying further service to legitimate users.
This vulnerability is related to the issue described in BID 23127 (CUPS Partial SSL Connection Remote Denial of Service Vulnerability).
CUPS is prone to an unspecified remote denial-of-service vulnerability when handling SSL connection requests.
Successfully exploiting this issue allows remote attackers to cause the affected service to crash, denying further service to legitimate users.
This vulnerability is related to the issue described in BID 23127 (CUPS Partial SSL Connection Remote Denial of Service Vulnerability).
Exploit / POC
CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.
References
CUPS SSL Negotiation Unspecified Remote Denial of Service Vulnerability
References:
References:
- CUPS Product Page (Easy Software Products)
- Avaya Security Advisory ASA-2007-476 (Avaya)
- RHSA-2007:1022-2 cups security update (Red Hat)
- RHSA-2007:1023-2 cups security update (Red Hat)