PT-2008-1013 · Apple+1 · Cups+1

Dean Reges

·

Publicado

2008-03-18

·

Atualizado

2024-06-15

·

CVE-2008-1722

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.2.12-r8 CUPS versions 1.3
Description The issue involves multiple integer overflows in the CUPS package, specifically in the filter/image-png.c and filter/image-zoom.c files, which can be exploited to cause a denial of service and trigger memory corruption. This can be achieved by using a crafted PNG image. The vulnerability can be exploited remotely and may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For CUPS versions prior to 1.2.12-r8, update to version 1.2.12-r8 or later to resolve the issue. For CUPS version 1.3, consider disabling the filter/image-png.c and filter/image-zoom.c functions until a patch is available. As a temporary workaround, restrict access to the CUPS service to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01436
BDU:2015-09638
CVE-2008-1722
DSA-1625-1
OPENSUSE-SU-2024:10707-1
RHSA-2008:0498
RHSA-2008_0498

Produtos afetados

Cups
Red Hat