CVE-2007-4351: Buffer Overflow
Published Oct 31, 2007
·Updated
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Affected Software
1 affected component
cups CUPS<=1.3.3
Remediation
Patch Available
Event History
Oct 31, 2007
CVE Published
10:46 PM
Nov 1, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4351?
CVE-2007-4351 is classified as a high severity vulnerability due to the potential for remote attackers to cause a denial of service.
2
How do I fix CVE-2007-4351?
To fix CVE-2007-4351, update CUPS to a version newer than 1.3.3 that addresses this vulnerability.
3
What types of attacks are possible with CVE-2007-4351?
CVE-2007-4351 allows attackers to perform denial of service attacks by exploiting stack-based buffer overflow.
4
In which versions of CUPS is CVE-2007-4351 present?
CVE-2007-4351 is present in CUPS version 1.3.3 and earlier.
5
Which components are affected by CVE-2007-4351?
CVE-2007-4351 affects the ippReadIO function in the cups/ipp.c file.