LWN.net Logo

cups: arbitrary code execution

Package(s):cups CVE #(s):CVE-2008-1722
Created:April 21, 2008 Updated:December 22, 2008
Description:

From the Gentoo advisory:

Thomas Pollet reported a possible integer overflow vulnerability in the PNG image handling in the file filter/image-png.c.

A malicious user might be able to execute arbitrary code with the privileges of the user running CUPS (usually lp), or cause a Denial of Service by sending a specially crafted PNG image to the print server. The vulnerability is exploitable via the network if CUPS is sharing printers remotely.

Alerts:
rPath rPSA-2008-0338-1 2008-12-19
Ubuntu USN-656-1 2008-10-15
Fedora FEDORA-2008-8844 2008-10-16
Fedora FEDORA-2008-8801 2008-10-16
Mandriva MDVSA-2008:170 2007-08-13
Debian DSA-1625-1 2008-08-01
CentOS CESA-2008:0498 2008-06-04
Red Hat RHSA-2008:0498-01 2008-06-04
Fedora FEDORA-2008-3756 2008-05-13
Fedora FEDORA-2008-3586 2008-05-09
Fedora FEDORA-2008-3449 2008-05-09
Ubuntu USN-606-1 2008-05-05
Gentoo 200804-23 2008-04-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds