First published: Tue Apr 01 2008(Updated: )
The Common UNIX Printing System (CUPS) provides a portable printing layer<br>for UNIX(R) operating systems.<br>Two overflows were discovered in the HP-GL/2-to-PostScript filter. An<br>attacker could create a malicious HP-GL/2 file that could possibly execute<br>arbitrary code as the "lp" user if the file is printed. (CVE-2008-0053)<br>A buffer overflow flaw was discovered in the GIF decoding routines used by<br>CUPS image converting filters "imagetops" and "imagetoraster". An attacker<br>could create a malicious GIF file that could possibly execute arbitrary<br>code as the "lp" user if the file was printed. (CVE-2008-1373)<br>It was discovered that the patch used to address CVE-2004-0888 in CUPS<br>packages in Red Hat Enterprise Linux 3 and 4 did not completely resolve the<br>integer overflow in the "pdftops" filter on 64-bit platforms. An attacker<br>could create a malicious PDF file that could possibly execute arbitrary<br>code as the "lp" user if the file was printed. (CVE-2008-1374)<br>All cups users are advised to upgrade to these updated packages, which<br>contain backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cups | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
redhat/cups | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
redhat/cups-devel | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
redhat/cups-libs | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
redhat/cups-libs | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
redhat/cups-devel | <1.1.22-0.rc1.9.20.2.el4_6.6 | 1.1.22-0.rc1.9.20.2.el4_6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2008:0206 is classified as critical due to the potential for arbitrary code execution.
To fix RHSA-2008:0206, update the CUPS package to version 1.1.22-0.rc1.9.20.2.el4_6.6 or later.
RHSA-2008:0206 affects various versions of the CUPS packages, including cups, cups-devel, and cups-libs on Red Hat Enterprise Linux EL4.
RHSA-2008:0206 is associated with buffer overflow vulnerabilities in the HP-GL/2-to-PostScript filter.
Yes, potential exploits exist that could allow attackers to execute arbitrary code via crafted HP-GL/2 files.