The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-09-13 22:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-2874
Mitre link : CVE-2005-2874
CVE.ORG link : CVE-2005-2874
JSON object : View
Products Affected
easy_software_products
- cups
CWE