CVE-2004-1267: Buffer Overflow
Published Dec 22, 2004
·Updated
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Affected Software
24 affected components
Easy Software Products Cups=1.0.4
Easy Software Products Cups=1.0.4_8
Easy Software Products Cups=1.1.1
Easy Software Products Cups=1.1.4
Easy Software Products Cups=1.1.4_2
Easy Software Products Cups=1.1.4_3
Easy Software Products Cups=1.1.4_5
Easy Software Products Cups=1.1.6
Easy Software Products Cups=1.1.7
Easy Software Products Cups=1.1.10
Easy Software Products Cups=1.1.12
Easy Software Products Cups=1.1.13
Easy Software Products Cups=1.1.14
Easy Software Products Cups=1.1.15
Easy Software Products Cups=1.1.16
Easy Software Products Cups=1.1.17
Easy Software Products Cups=1.1.18
Easy Software Products Cups=1.1.19
Easy Software Products Cups=1.1.19_rc5
Easy Software Products Cups=1.1.20
Easy Software Products Cups=1.1.21
Easy Software Products Cups=1.1.22_rc1
redhat Fedora Core=core_2.0
redhat Fedora Core=core_3.0
Event History
Dec 22, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1267?
CVE-2004-1267 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2004-1267?
To fix CVE-2004-1267, update your CUPS software to a version that is not vulnerable, ideally the latest release.
3
What versions of CUPS are affected by CVE-2004-1267?
CVE-2004-1267 affects CUPS versions from 1.0.4 up to 1.1.22.
4
What is the impact of exploiting CVE-2004-1267?
Exploitation of CVE-2004-1267 could allow an attacker to execute arbitrary code on the affected system.
5
Who is primarily affected by CVE-2004-1267?
Users and administrators running vulnerable versions of CUPS, particularly in server environments, are primarily affected by CVE-2004-1267.