CVE-2008-3639: Buffer Overflow
Heap-based buffer overflow in the readrle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3639?
CVE-2008-3639 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2008-3639?
To fix CVE-2008-3639, upgrade CUPS to version 1.3.9 or later, as it contains the necessary patches.
What versions of CUPS are affected by CVE-2008-3639?
CVE-2008-3639 affects CUPS versions prior to 1.3.9 and several earlier versions including 1.1 and versions up to 1.3.8.
What is the exploit method for CVE-2008-3639?
The vulnerability can be exploited through specially crafted SGI images with malformed Run Length Encoded data.
Who is vulnerable to CVE-2008-3639?
Any system running the affected versions of CUPS prior to 1.3.9 is at risk of CVE-2008-3639.