Mandrake Linux Security Advisory : cups (MDKSA-2003:062)

Medium Nessus Plugin ID 14045


The remote Mandrake Linux host is missing one or more security updates.


A Denial of Service (DoS) vulnerability was discovered in the CUPS printing system by Phil D'Amore of Red Hat. The IPP (Internet Printing Protocol) that CUPS uses is single-threaded and can only service one request at a time. A malicious user could create a partial request that does not time out and cause a Denial of Service condition where CUPS will not respond to other printing requests. This can only be done if the malicious user can create a TCP connection to the IPP port (631 by default).

This vulnerability has been fixed upstream in CUPS 1.1.19 and packages of previous versions have been fixed to correct the problem.


Update the affected packages.

Plugin Details

Severity: Medium

ID: 14045

File Name: mandrake_MDKSA-2003-062.nasl

Version: $Revision: 1.14 $

Type: local

Published: 2004/07/31

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:cups, p-cpe:/a:mandriva:linux:cups-common, p-cpe:/a:mandriva:linux:cups-serial, p-cpe:/a:mandriva:linux:libcups1, p-cpe:/a:mandriva:linux:libcups1-devel, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0, cpe:/o:mandrakesoft:mandrake_linux:9.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2003/05/29

Reference Information

CVE: CVE-2003-0195

MDKSA: 2003:062