CUPS Cupsd Request Method Denial Of Service Vulnerability

BID:7637

Info

CUPS Cupsd Request Method Denial Of Service Vulnerability

Bugtraq ID: 7637
Class: Design Error
CVE: CVE-2003-0195
Remote: Yes
Local: No
Published: May 20 2003 12:00AM
Updated: Jul 11 2009 10:06PM
Credit: Discovery of this vulnerability has been credited to Phil D'Amore of Red Hat.
Vulnerable: Terra Soft Solutions Yellow Dog Linux 3.0
Slackware Linux 9.0
Slackware Linux 8.1
Slackware Linux -current
Redhat Linux 9.0 i386
Redhat Linux 8.0 i386
Redhat Linux 7.3 i386
Mandriva Linux Mandrake 9.1 ppc
Mandriva Linux Mandrake 9.1
Mandriva Linux Mandrake 9.0
Mandriva Linux Mandrake 8.2 ppc
Mandriva Linux Mandrake 8.2
MandrakeSoft Multi Network Firewall 2.0
MandrakeSoft Corporate Server 2.1
Easy Software Products CUPS 1.1.19
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Home
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Workstation 8.0
Easy Software Products CUPS 1.1.18
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Mandriva Linux Mandrake 9.0
+ S.u.S.E. Linux Personal 8.2
Easy Software Products CUPS 1.1.17
+ Redhat Desktop 3.0
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
Easy Software Products CUPS 1.1.16
+ Mandriva Linux Mandrake 9.0
Easy Software Products CUPS 1.1.15
+ Conectiva Linux Enterprise Edition 1.0
+ SuSE Linux 8.1
Easy Software Products CUPS 1.1.14
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
Easy Software Products CUPS 1.1.12
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
Easy Software Products CUPS 1.1.10
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Workstation 3.1.1
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
Easy Software Products CUPS 1.1.6
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
Not Vulnerable: Easy Software Products CUPS 1.1.19 rc5
DrPhibez and Nitro187 Guild FTPD 1.1.19 rc5

Discussion

CUPS Cupsd Request Method Denial Of Service Vulnerability

The cupsd has been reported prone to a denial of service vulnerability.

Reportedly the cupsd does not adequately apply a time-out process for malicious HTTP requests and service is denied to subsequent cupsd requests.

This issue may be exploited by remote attackers to deny cupsd service to valid users.

Exploit / POC

CUPS Cupsd Request Method Denial Of Service Vulnerability

The following proof of concept exploit was discovered by [email protected]:

$ telnet <your_favorite_cups_server> ipp
POST /printers/<your_favorite_printer> HTTP/1.1

Don't enter the second carriage return to complete the headers, just the POST line and one carriage return.

Solution / Fix

CUPS Cupsd Request Method Denial Of Service Vulnerability

Solution:
The vendor has released patches to address this issue.

Conectiva has released advisory CLA-2003:702 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.

Conectiva has released an advisory (CLSA-2003:678) and fixes to address this issue. See referenced advisory for further detail.

SuSE has released security advisory (SuSE-SA:2003:028) to address this issue. Fixes are available below.

Red Hat has released security advisory RHSA-2003:171-01 to address this issue. Fixes are available below.

Turbolinux has released an advisory (TLSA-2003-33) to address this issue. Turbolinux have advised customers to use the turbopkg tool to apply the update. See attached advisory for further details relating to obtaining and applying fixes.

Mandrake has release advisory MDKSA-2003:062 to address this issue. See referenced advisory for fix information.

Debian has released an advisory (DSA 317-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Gentoo has released advisory 200306-09. Affected users are advised to perform the following actions:

emerge sync
emerge cups
emerge clean


Slackware Linux -current

Easy Software Products CUPS 1.1.10

Easy Software Products CUPS 1.1.12

Easy Software Products CUPS 1.1.14

Easy Software Products CUPS 1.1.15

Easy Software Products CUPS 1.1.16

Easy Software Products CUPS 1.1.18

Easy Software Products CUPS 1.1.19

Easy Software Products CUPS 1.1.6

Terra Soft Solutions Yellow Dog Linux 3.0

Redhat Linux 7.3 i386

Redhat Linux 8.0 i386

Slackware Linux 8.1

Redhat Linux 9.0 i386

Slackware Linux 9.0

References

CUPS Cupsd Request Method Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report