LWN.net Logo

cupsys: arbitrary code execution

Package(s):cupsys CVE #(s):CVE-2008-5286
Created:December 3, 2008 Updated:January 26, 2009
Description:

From the Debian advisory:

An integer overflow has been discovered in the image validation code of cupsys, the Common UNIX Printing System. An attacker could trigger this bug by supplying a malicious graphic that could lead to the execution of arbitrary code.

Alerts:
rPath rPSA-2008-0338-1 2008-12-19
CentOS CESA-2008:1028 2008-12-15
Red Hat RHSA-2008:1028-01 2008-12-15
Gentoo 200812-11 2008-12-10
Debian DSA-1677-1 2008-12-02
Mandriva MDVSA-2009:029 2009-01-24
Mandriva MDVSA-2009:028 2009-01-24
SuSE SUSE-SR:2009:002 2009-01-19
Ubuntu USN-707-1 2009-01-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds