LWN.net Logo

cups: several vulnerabilities

Package(s):cups CVE #(s):CVE-2008-3639 CVE-2008-3640 CVE-2008-3641
Created:October 10, 2008 Updated:February 20, 2009
Description: From the Red Hat advisory:

A buffer overflow flaw was discovered in the SGI image format decoding routines used by the CUPS image converting filter "imagetops". An attacker could create a malicious SGI image file that could, possibly, execute arbitrary code as the "lp" user if the file was printed. (CVE-2008-3639)

An integer overflow flaw leading to a heap buffer overflow was discovered in the Text-to-PostScript "texttops" filter. An attacker could create a malicious text file that could, possibly, execute arbitrary code as the "lp" user if the file was printed. (CVE-2008-3640)

An insufficient buffer bounds checking flaw was discovered in the HP-GL/2-to-PostScript "hpgltops" filter. An attacker could create a malicious HP-GL/2 file that could, possibly, execute arbitrary code as the "lp" user if the file was printed. (CVE-2008-3641)

Alerts:
CentOS CESA-2009:0308 2009-02-19
Red Hat RHSA-2009:0308-01 2009-02-19
rPath rPSA-2008-0338-1 2008-12-19
Gentoo 200812-11 2008-12-10
Slackware SSA:2008-312-01 2008-11-07
Debian DSA-1656-1 2008-10-20
SuSE SUSE-SR:2008:021 2008-10-17
Ubuntu USN-656-1 2008-10-15
Fedora FEDORA-2008-8844 2008-10-16
Fedora FEDORA-2008-8801 2008-10-16
Mandriva MDVSA-2008:211 2007-10-10
CentOS CESA-2008:0937 2008-10-10
Red Hat RHSA-2008:0937-01 2008-10-10
SuSE SUSE-SR:2009:002 2009-01-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds