PT-2014-1888 · Openprinting+1 · Cups-Filters+1

Florian Weimer

·

Published

2014-03-12

·

Updated

2024-06-15

·

CVE-2013-6473

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups-filters versions 1.0.25 through 1.0.47 cups-filters versions prior to 1.0.53
Description The issue is related to multiple heap-based buffer overflows in the urftopdf filter. This can be exploited by remote attackers to execute arbitrary code via a large page or line in a URF file. The vulnerability may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For versions 1.0.25 through 1.0.47, update to version 1.0.47 or later. For versions prior to 1.0.53, update to version 1.0.53 or later. As a temporary workaround, consider restricting access to the urftopdf filter until a patch is available.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1278
BDU:2015-09753
CVE-2013-6473
MGASA-2014-0170
OPENSUSE-SU-2024:10313-1

Affected Products

Alt Linux
Cups-Filters