LWN.net Logo

cups: multiple vulnerabilities

Package(s):cups CVE #(s):CVE-2008-1374 CVE-2004-0888 CVE-2005-0206
Created:April 1, 2008 Updated:August 6, 2008
Description: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code. An attacker could create a malicious PDF file that could possibly execute arbitrary code as the "lp" user if the file was printed. The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
Alerts:
rPath rPSA-2008-0245-1 2008-08-05
Red Hat RHSA-2008:0206-01 2008-04-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds