PT-2002-3143 · Foo+1 · Xpdf+1

Publicado

1970-01-01

·

Atualizado

2018-05-03

·

CVE-2002-1384

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.1.18 Xpdf versions prior to 2.01
Description The issue is related to multiple vulnerabilities in the CUPS and Xpdf packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely or by local users. The vulnerabilities are caused by an integer overflow in the pdftops component, which allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements.
Recommendations For CUPS versions prior to 1.1.18, update to version 1.1.18 or later to resolve the issue. For Xpdf versions prior to 2.01, update to version 2.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the pdftops component until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01804
BDU:2015-01805
BDU:2015-03487
BDU:2015-07982
BDU:2015-07983
BDU:2015-07984
BDU:2015-07985
BDU:2015-07986
BDU:2015-07987
CVE-2002-1384
DSA-222
DSA-232

Produtos afetados

Cups
Xpdf