Overview
CUPS contains an integer overflow that may allow a remote attacker to cause a vulnerable system to crash.
Description
The Common Unix Printing System (CUPS) is a print server that is used and distributed by many Unix-like operating systems. CUPS contains an integer overflow vulnerability that occurs in its image processing library. From the CUPS bug tracker: |
Impact
Users who obtain CUPS from their operating system vendor should see the systems affected portion of this document for a partial list of affected vendors. |
Solution
Upgrade Versions newer than 1.3.7 available from the CUPS SVN server have applied a fix to address this issue. Users who obtain CUPS from their operating system vendor should see the systems affected portion of this document for more details. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cups.org/str.php?L2790
- http://www.cups.org/software.php
- http://www.cups.org/documentation.php/man-cupsd.conf.html
- https://www.securecoding.cert.org/confluence/display/seccode/INT32-C.+Ensure+that+operations+on+signed+integers+do+not+result+in+overflow
- http://en.wikipedia.org/wiki/Integer_overflow
Acknowledgements
This document was written by Dean Reges.
Other Information
CVE IDs: | CVE-2008-1722 |
Severity Metric: | 8.33 |
Date Public: | 2008-04-15 |
Date First Published: | 2008-04-25 |
Date Last Updated: | 2008-04-30 15:38 UTC |
Document Revision: | 41 |