View at Official ubuntu advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2005-2874 medium priority: Ubuntu including 1 source packages (cupsys), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): not-affected 3, needs-triage 1.
The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.