PT-2002-3143 · Foo+1 · Xpdf+1

Published

1970-01-01

·

Updated

2018-05-03

·

CVE-2002-1384

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.1.18 Xpdf versions prior to 2.01
Description The issue is related to multiple vulnerabilities in the CUPS and Xpdf packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely or by local users. The vulnerabilities are caused by an integer overflow in the pdftops component, which allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements.
Recommendations For CUPS versions prior to 1.1.18, update to version 1.1.18 or later to resolve the issue. For Xpdf versions prior to 2.01, update to version 2.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the pdftops component until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01804
BDU:2015-01805
BDU:2015-03487
BDU:2015-07982
BDU:2015-07983
BDU:2015-07984
BDU:2015-07985
BDU:2015-07986
BDU:2015-07987
CVE-2002-1384
DSA-222
DSA-232

Affected Products

Cups
Xpdf