PT-2008-1013 · Apple+1 · Cups+1

Dean Reges

·

Published

2008-03-18

·

Updated

2024-06-15

·

CVE-2008-1722

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.2.12-r8 CUPS versions 1.3
Description The issue involves multiple integer overflows in the CUPS package, specifically in the filter/image-png.c and filter/image-zoom.c files, which can be exploited to cause a denial of service and trigger memory corruption. This can be achieved by using a crafted PNG image. The vulnerability can be exploited remotely and may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For CUPS versions prior to 1.2.12-r8, update to version 1.2.12-r8 or later to resolve the issue. For CUPS version 1.3, consider disabling the filter/image-png.c and filter/image-zoom.c functions until a patch is available. As a temporary workaround, restrict access to the CUPS service to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01436
BDU:2015-09638
CVE-2008-1722
DSA-1625-1
OPENSUSE-SU-2024:10707-1
RHSA-2008:0498
RHSA-2008_0498

Affected Products

Cups
Red Hat