CVE-2005-2874
EPSS 1.4%
Description
The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.
How to fix CVE-2005-2874
To remediate CVE-2005-2874, upgrade the affected package to a fixed version below.
- Debian/cups—upgrade to 1.1.23-1 or later
Is CVE-2005-2874 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.23-1