CVE-2008-5183 is a denial-of-service vulnerability affecting CUPS versions 1.3.9 and earlier, including implementations by Apple, Debian, and OpenSUSE. It allows local users, and potentially remote attackers leveraging CVE-2008-5184, to crash the cupsd daemon by adding a large number of RSS subscriptions, leading to a NULL pointer dereference. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, resulting in high availability impact. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an ExploitDB entry (EDB-7150) exists, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.9CPE matchmatch criteria | cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:* | ||
< 10.5.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 10.5.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.