PT-2014-1812 · Openprinting+3 · Cups-Filters+3

Publicado

2014-05-08

·

Atualizado

2024-06-15

·

CVE-2014-4337

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions cups-filters versions 1.0.35 through 1.0.52
Description The issue is related to multiple vulnerabilities in the cups-filters package, which can lead to a denial of service and disruption of protected information availability. These vulnerabilities can be exploited remotely. The process browse data function in utils/cups-browsed.c is specifically mentioned as allowing remote attackers to cause an out-of-bounds read and application crash via crafted packet data.
Recommendations For cups-filters versions 1.0.35 through 1.0.52, update to version 1.0.53 or later to resolve the issue. As a temporary workaround, consider restricting access to the cups-browsed utility until a patch is available. Avoid using the process browse data function in utils/cups-browsed.c until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1665
BDU:2015-06081
BDU:2015-06082
BDU:2015-06083
BDU:2015-06084
BDU:2015-09199
BDU:2015-09200
BDU:2015-09201
BDU:2015-09202
CESA-2014_1795
CVE-2014-4337
MGASA-2014-0267
OPENSUSE-SU-2024:10313-1
RHSA-2014:1795
RHSA-2014_1795
USN-2210-1

Produtos afetados

Alt Linux
Centos
Red Hat
Cups-Filters