PT-2009-6728 · Apple+3 · Cups-Libs-X86+11

Braden Thomas

+1

·

Publicado

1970-01-01

·

Atualizado

2019-03-06

·

CVE-2009-0166

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups versions prior to 1.3.10 cups-libs (affected versions not specified) cups-libs-32bit (affected versions not specified) cups-libs-x86 (affected versions not specified) cups-client (affected versions not specified) cups-debuginfo (affected versions not specified) cups-debugsource (affected versions not specified) cups-devel (affected versions not specified) kdegraphics-3.5.4 (affected versions not specified) kdegraphics-devel-3.5.4 (affected versions not specified) Xpdf version 3.02pl2 and earlier
Description The issue concerns multiple vulnerabilities in various packages, including cups and kdegraphics, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, allows remote attackers to cause a denial of service via a crafted PDF file.
Recommendations For cups versions prior to 1.3.10, update to version 1.3.10 or later. For cups-libs, cups-libs-32bit, cups-libs-x86, cups-client, cups-debuginfo, cups-debugsource, and cups-devel, there is no information about a newer version that contains a fix for this vulnerability. For kdegraphics-3.5.4 and kdegraphics-devel-3.5.4, there is no information about a newer version that contains a fix for this vulnerability. For Xpdf version 3.02pl2 and earlier, update to a version later than 3.02pl2. As a temporary workaround, consider disabling the JBIG2 decoder function until a patch is available.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04161
BDU:2015-04162
BDU:2015-04163
BDU:2015-04164
BDU:2015-04165
BDU:2015-04166
BDU:2015-04167
BDU:2015-04168
BDU:2015-06216
BDU:2015-06220
BDU:2015-08480
BDU:2015-08481
BDU:2015-09375
CVE-2009-0166
DSA-1790-1
DSA-1793-1
RHSA-2009:0429
RHSA-2009:0430
RHSA-2009:0431
RHSA-2009:0458
RHSA-2009:0480
RHSA-2009_0429
RHSA-2009_0430
RHSA-2009_0431
RHSA-2009_0458
RHSA-2009_0480
RHSA-2010:0399
RHSA-2010:0400
RHSA-2010_0399
RHSA-2010_0400

Produtos afetados

Red Hat
Xpdf
Cups
Cups-Client
Cups-Debuginfo
Cups-Debugsource
Cups-Devel
Cups-Libs
Cups-Libs-32Bit
Cups-Libs-X86
Kdegraphics
Kdegraphics-Devel