LWN.net Logo

cups: arbitrary code execution

Package(s):cups CVE #(s):CVE-2008-1722
Created:April 21, 2008 Updated:June 4, 2008
Description:

From the Gentoo advisory:

Thomas Pollet reported a possible integer overflow vulnerability in the PNG image handling in the file filter/image-png.c.

A malicious user might be able to execute arbitrary code with the privileges of the user running CUPS (usually lp), or cause a Denial of Service by sending a specially crafted PNG image to the print server. The vulnerability is exploitable via the network if CUPS is sharing printers remotely.

Alerts:
Gentoo 200804-23 2008-04-18
Ubuntu USN-606-1 2008-05-05
Fedora FEDORA-2008-3449 2008-05-09
Fedora FEDORA-2008-3586 2008-05-09
Fedora FEDORA-2008-3756 2008-05-13
Red Hat RHSA-2008:0498-01 2008-06-04
CentOS CESA-2008:0498 2008-06-04

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.