{ "schema_version": "1.4.0", "id": "GHSA-hv7x-wq9f-458x", "modified": "2022-05-17T05:10:00Z", "published": "2022-05-17T05:10:00Z", "aliases": [ "CVE-2010-2432" ], "details": "The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2432" }, { "type": "WEB", "url": "http://cups.org/articles.php?L596" }, { "type": "WEB", "url": "http://cups.org/str.php?L3518" }, { "type": "WEB", "url": "http://secunia.com/advisories/43521" }, { "type": "WEB", "url": "http://security.gentoo.org/glsa/glsa-201207-10.xml" }, { "type": "WEB", "url": "http://www.debian.org/security/2011/dsa-2176" }, { "type": "WEB", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:146" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2011/0535" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-06-22T20:30:00Z" } }