FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2874

This CVE name corresponds to:

Entered Topic
2005-01-18 cups-base -- CUPS server remote DoS vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2874
Phase Assigned(20050913)

Description

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

References

Source Reference
CONFIRM http://www.cups.org/str.php?L1042+P0+S-1+C0+I0+E0+Q1042
CONFIRM http://www.cups.org/relnotes.php#010123
FEDORA FEDORA-2005-908
REDHAT RHSA-2005:772
MISC https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168072
OVAL oval:org.mitre.oval:def:9774
SECTRACK 1012811