Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Last updated 25 August 2025
Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by the cupsgetdestoptions function in phpcups.c.
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Hi all,
We thank all the researchers for the reports!
Have a nice day,
Zdenek -- Zdenek Dohnal Senior Software Engineer Red Hat, BRQ-TPBC