PT-2008-1101 · Apple · Cups

Iankko

+1

·

Publicado

2008-12-01

·

Atualizado

2017-09-29

·

CVE-2008-5286

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CUPS versions 1.1.17 through 1.3.9
Description The issue concerns multiple vulnerabilities in the CUPS package that can be exploited remotely, potentially leading to breaches in confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the cupsImageReadPNG function allows remote attackers to execute arbitrary code via a PNG image with a large height value, bypassing validation checks and triggering a buffer overflow.
Recommendations For CUPS versions 1.1.17 through 1.3.9, update to a version newer than 1.3.9 to resolve the issue. As a temporary workaround, consider restricting the use of PNG images or disabling the cupsImageReadPNG function until a patch is available. Avoid using the height variable in the affected CUPS function to minimize the risk of exploitation.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09353
CVE-2008-5286
DSA-1677-1
RHSA-2008:1028

Produtos afetados

Cups