First published: Wed Oct 31 2007(Updated: )
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
CUPS libraries | <=1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4351 is classified as a high severity vulnerability due to the potential for remote attackers to cause a denial of service.
To fix CVE-2007-4351, update CUPS to a version newer than 1.3.3 that addresses this vulnerability.
CVE-2007-4351 allows attackers to perform denial of service attacks by exploiting stack-based buffer overflow.
CVE-2007-4351 is present in CUPS version 1.3.3 and earlier.
CVE-2007-4351 affects the ippReadIO function in the cups/ipp.c file.