PT-2002-3150 · Apple · Cups
Published
1970-01-01
·
Updated
2016-10-18
·
CVE-2002-1383
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CUPS versions 1.1.14 through 1.1.17
Description
The issue involves multiple integer overflows in the Common Unix Printing System (CUPS), which can be exploited remotely to execute arbitrary code. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can occur via the CUPSd HTTP interface and the image handling code in CUPS filters.
Recommendations
For CUPS versions 1.1.14 through 1.1.17, consider disabling the CUPSd HTTP interface and restricting access to the image handling code in CUPS filters until a patch is available. As a temporary workaround, restrict access to the vulnerable CUPS filters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cups