Bug 232243 - CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server
CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecti...
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: cups (Show other bugs)
5
All Linux
high Severity high
: ---
: ---
Assigned To: Tim Waugh
http://lists.apple.com/archives/secur...
impact=moderate,source=cve,reported=2...
: Security
Depends On: 232241
Blocks:
  Show dependency treegraph
 
Reported: 2007-03-14 11:32 EDT by Lubomir Kundrak
Modified: 2008-02-22 05:28 EST (History)
0 users

See Also:
Fixed In Version: 1.2.8-1.fc5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-02-22 05:28:13 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Lubomir Kundrak 2007-03-14 11:32:48 EDT
+++ This bug was initially created as a clone of Bug #232241 +++

Description of problem:

CUPS doesn't use separate workers for connections. During SSL
negotiation it does not accept new connections from anyone so
any user can DoS the server with unfinished negotiation.

Version-Release number of selected component (if applicable):

Both 1.2 <= 1.2.7 and 1.1 are affected.
I was able to reproduce on RHEL4, RHEL5.
FC6 (1.2.7) is already fixed.

How reproducible:

SSL support needs to be enabled. Default in 1.2.

Steps to Reproduce:
1. Launch the attached reproducer (eventually modify appropriately)
2. Let it run for at least 10 secs (to ensure that the server is not patched)
3. Attempt another connection to the CUPS server.
  
Actual results:

Hang.

Additional info:

The relevant fix:
http://www.cups.org/articles.php?L429+I10+T+P1+Q (r6110, r6081, r6079)

-- Additional comment from lkundrak@redhat.com on 2007-03-14 11:29 EST --
Created an attachment (id=150051)
CVE-2007-0720 CUPS incomplete SSL negotiation DoS reproducer

For 1.1, you'll likely use a different port number.
Comment 1 Tomas Hoger 2008-02-22 05:15:08 EST
This was fixed for cups in Red Hat Enterprise Linux 5 in:

  https://rhn.redhat.com/errata/RHSA-2007-0123.html

Tim, ok to close this one?
Comment 2 Tim Waugh 2008-02-22 05:28:13 EST
Yes.

Note You need to log in before you can comment on or make changes to this bug.