Vulnerability Name:
CVE-2003-0788 (CCN-13584)
Assigned:
2003-06-24
Published:
2003-06-24
Updated:
2017-07-11
Summary:
Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Low
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Denial of Service
References:
Source: CCN
Type: Bugzilla Bug 97958
IPP at 100% processor doing nothing useful.
Source: MISC
Type: UNKNOWN
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958
Source: MITRE
Type: CNA
CVE-2003-0788
Source: CONECTIVA
Type: UNKNOWN
CLA-2003:779
Source: CONECTIVA
Type: UNKNOWN
CLA-2003:788
Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2003:779
cups
Source: CCN
Type: RHSA-2003-275
Updated CUPS packages fix denial of service
Source: CCN
Type: SA10123
CUPS Unspecified Denial of Service Vulnerability
Source: SECUNIA
Type: UNKNOWN
10123
Source: CCN
Type: CUPS Web site
Software - Common UNIX Printing System
Source: CCN
Type: SCO Security Advisory CSSA-2004-012.0
OpenLinux: cups denial of service vulnerability
Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:104
Source: CCN
Type: OSVDB ID: 2761
CUPS Unspecified DoS
Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2003:275
Source: BID
Type: Patch, Vendor Advisory
8952
Source: CCN
Type: BID-8952
Cups Internet Printing Protocol Job Loop Denial Of Service Vulnerability
Source: CCN
Type: TLSA-2003-63
cups denial of service attack
Source: TURBO
Type: UNKNOWN
TLSA-2003-63
Source: XF
Type: UNKNOWN
cups-ipp-dos(13584)
Source: XF
Type: UNKNOWN
cups-ipp-dos(13584)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:easy_software_products:cups:1.0.4:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.0.4_8:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.1:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.4:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.4_2:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.4_3:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.4_5:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.6:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.7:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.10:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.12:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.13:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.14:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.15:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.16:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.17:*:*:*:*:*:*:*
OR
cpe:/a:easy_software_products:cups:1.1.18:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:easy_software_products:cups:1.1.19:*:*:*:*:*:*:*
AND
cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:8.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:8.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:9.0:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:9.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20030788
V
CVE-2003-0788
2015-11-16
BACK
easy_software_products
cups 1.0.4
easy_software_products
cups 1.0.4_8
easy_software_products
cups 1.1.1
easy_software_products
cups 1.1.4
easy_software_products
cups 1.1.4_2
easy_software_products
cups 1.1.4_3
easy_software_products
cups 1.1.4_5
easy_software_products
cups 1.1.6
easy_software_products
cups 1.1.7
easy_software_products
cups 1.1.10
easy_software_products
cups 1.1.12
easy_software_products
cups 1.1.13
easy_software_products
cups 1.1.14
easy_software_products
cups 1.1.15
easy_software_products
cups 1.1.16
easy_software_products
cups 1.1.17
easy_software_products
cups 1.1.18
easy_software_products
cups 1.1.19
redhat
linux 7
redhat
linux 7.1
conectiva
linux 7.0
redhat
linux 7.2
conectiva
linux 8.0
redhat
linux 7.3
redhat
linux 8.0
mandrakesoft
mandrake linux 9.0
mandrakesoft
mandrake linux corporate server 2.1
redhat
linux 9.0
conectiva
linux 9.0
mandrakesoft
mandrake linux corporate server 2.1