PT-2008-1012 · Apple+1 · Cups+1
Tomas Hoger
·
Publicado
2008-03-18
·
Atualizado
2018-10-11
·
CVE-2008-1373
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CUPS versions prior to 1.2.12-r7
cups versions 1.3.6
Description
The issue involves multiple vulnerabilities in the CUPS package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. A buffer overflow vulnerability exists in the
gif read lzw function, allowing remote attackers to have an unknown impact via a GIF file with a large code size value.Recommendations
For CUPS versions prior to 1.2.12-r7, update to version 1.2.12-r7 or later to resolve the issue.
For CUPS version 1.3.6, consider disabling the
gif read lzw function as a temporary workaround until a patch is available.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cups
Red Hat