PT-2014-1812 · Openprinting+3 · Cups-Filters+3
Published
2014-05-08
·
Updated
2024-06-15
·
CVE-2014-4337
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
cups-filters versions 1.0.35 through 1.0.52
Description
The issue is related to multiple vulnerabilities in the cups-filters package, which can lead to a denial of service and disruption of protected information availability. These vulnerabilities can be exploited remotely. The
process browse data function in utils/cups-browsed.c is specifically mentioned as allowing remote attackers to cause an out-of-bounds read and application crash via crafted packet data.Recommendations
For cups-filters versions 1.0.35 through 1.0.52, update to version 1.0.53 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
cups-browsed utility until a patch is available.
Avoid using the process browse data function in utils/cups-browsed.c until the issue is resolved.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Cups-Filters