Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5183 to the following vulnerability: cupsd in CUPS before 1.3.8 allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5183 http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/ https://bugs.launchpad.net/ubuntu/+source/cups/+bug/298241 http://www.openwall.com/lists/oss-security/2008/11/19/3 http://www.openwall.com/lists/oss-security/2008/11/19/4 Patch: See attachment -- cups-1.3-max-subscriptions.patch
cups-1.3.9-4.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/cups-1.3.9-4.fc10
cups-1.3.9-2.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/cups-1.3.9-2.fc9
cups-1.3.9-2.fc8 has been submitted as an update for Fedora 8. http://admin.fedoraproject.org/updates/cups-1.3.9-2.fc8
cups-1.3.9-4.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
cups-1.3.9-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
cups-1.3.9-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
https://www.redhat.com/security/data/cve/CVE-2008-5183.html
This was addressed via: Red Hat Enterprise Linux version 5 (RHSA-2008:1029)