← Back

CVE-2005-2874

nvd nist
Published: Sep 13, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

Affected (45)

Cups
Configuration A
45 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.1.10
Version 1.1.10_1
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16
Version 1.1.17
Version 1.1.18
Version 1.1.19
Version 1.1.19_rc1
Version 1.1.19_rc2
Version 1.1.19_rc3
Version 1.1.19_rc4
Version 1.1.19_rc5
Version 1.1.1
Version 1.1.20
Version 1.1.20_rc1
Version 1.1.20_rc2
Version 1.1.20_rc3
Version 1.1.20_rc4
Version 1.1.20_rc5
Version 1.1.20_rc6
Version 1.1.21
Version 1.1.21_rc1
Version 1.1.21_rc2
Version 1.1.22
Version 1.1.22_rc1
Version 1.1.22_rc2
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.5_1
Version 1.1.5_2
Version 1.1.6
Version 1.1.6_1
Version 1.1.6_2
Version 1.1.6_3
Version 1.1.7
Version 1.1.8
Version 1.1.9
Version 1.1.9_1
Version 1.1

References (14)

Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitPatchVendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.