CVE-2002-1384: Integer Overflow
Published Jan 2, 2003
·Updated
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Affected Software
20 affected components
xpdf Xpdf=2.0
Easy Software Products Cups=1.1.10
xpdf Xpdf=1.0
Easy Software Products Cups=1.1.7
xpdf Xpdf=0.91
Easy Software Products Cups=1.0.4_8
Easy Software Products Cups=1.1.13
xpdf Xpdf=1.0a
Easy Software Products Cups=1.1.17
Easy Software Products Cups=1.1.4_3
Easy Software Products Cups=1.1.4
xpdf Xpdf=2.1
xpdf Xpdf=0.90
Easy Software Products Cups=1.1.4_5
Easy Software Products Cups=1.1.1
Easy Software Products Cups=1.0.4
Easy Software Products Cups=1.1.14
Easy Software Products Cups=1.1.4_2
xpdf Xpdf=1.1
Easy Software Products Cups=1.1.6
Remediation
Patch Available
Event History
Jan 2, 2003
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1384?
CVE-2002-1384 has a high severity rating due to its potential to allow local users to execute arbitrary code.
2
How do I fix CVE-2002-1384?
To fix CVE-2002-1384, update CUPS or Xpdf to the latest versions that have patched this vulnerability.
3
Which versions of software are affected by CVE-2002-1384?
CVE-2002-1384 affects CUPS versions prior to 1.1.18 and Xpdf versions prior to 2.01.
4
Can CVE-2002-1384 be exploited remotely?
No, CVE-2002-1384 is a local vulnerability that requires access to the system to exploit.
5
What type of vulnerability is CVE-2002-1384?
CVE-2002-1384 is an integer overflow vulnerability that can lead to arbitrary code execution.