REDHAT-BUG-1235385: Buffer Overflow
A heap-based buffer overflow was discovered in the way the texttopdf utility of cups-filters processed print jobs with a specially crafted line size. An attacker being able to submit print jobs could exploit this flaw to crash texttopdf or, possibly, execute arbitrary code with the privileges of the 'lp' user.
Acknowledgements:
This issue was discovered by Petr Sklenar of Red Hat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1235385?
The severity of REDHAT-BUG-1235385 is high due to the potential for a heap-based buffer overflow that could allow an attacker to execute arbitrary code.
How do I fix REDHAT-BUG-1235385?
To fix REDHAT-BUG-1235385, update to the latest version of cups-filters that addresses this vulnerability.
Who is affected by REDHAT-BUG-1235385?
Users of the OpenPrinting cups-filters utility are affected by REDHAT-BUG-1235385.
What type of vulnerability is REDHAT-BUG-1235385?
REDHAT-BUG-1235385 is a heap-based buffer overflow vulnerability.
Can REDHAT-BUG-1235385 be exploited remotely?
Yes, REDHAT-BUG-1235385 can be exploited if an attacker can submit specially crafted print jobs.