VDB

CVE-2005-2874

CVE-2005-2874 PUBLISHED CVSS 5 MEDIUM

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

EPSS 2.97% · 85.9th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
2.97%
85.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
easy_software_productscups1.1, 1.1.1, 1.1.4

Timeline

  • Sep 13, 2005 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›