CVE-2002-1368
published 2002-12-26CVE-2002-1368: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by…
PriorityP264high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
15.47%
96.4th percentile
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| debian | cups | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /printers HTTP/1.1
Host: localhost
Authorization: Basic AAA
Transfer-Encoding: chunked
- - - - -FFFFFFFE↗
- →Detect HTTP POST requests to CUPS (port 631) containing a negative Content-Length header value, which triggers a negative memcpy() argument. ↗
- →Detect HTTP POST requests to CUPS (port 631) using chunked Transfer-Encoding with a negative chunk size (e.g., FFFFFFFE in hex), indicating exploitation of the chunked-encoding negative-length vector. ↗
- →This vulnerability was reported as actively exploited in the wild as of January 2003; prioritize detection on any CUPS 1.1.14–1.1.17 instances still exposed on port 631. ↗
- ·The exploit targets CUPS versions 1.1.14 through 1.1.17 only; versions fixed at 1.1.18-1 and later are not affected. ↗
- ·The exploit PoC connects directly to localhost:631, but the vulnerability is exploitable by any remote attacker who can reach the cupsd service on port 631; firewall rules restricting access to this port are a key mitigation. ↗
- ·Code execution impact may be platform-dependent; BSD systems are specifically called out as likely exploitable for arbitrary code execution beyond DoS. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-98r4-fx32-wmfw: Common Unix Printing System (CUPS) 1
ghsa_unreviewed·2022-05-03
CVE-2002-1368 [HIGH] GHSA-98r4-fx32-wmfw: Common Unix Printing System (CUPS) 1
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
OSV
CVE-2002-1368: Common Unix Printing System (CUPS) 1
osv·2002-12-26·CVSS 7.5
CVE-2002-1368 [HIGH] CVE-2002-1368: Common Unix Printing System (CUPS) 1
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
VulnCheck
easy_software_products cups Vulnerability
vulncheck·2002·CVSS 7.5
CVE-2002-1368 [HIGH] easy_software_products cups Vulnerability
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
Affected: easy_software_products cups
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.exploit-db.com/exploits/22106
Red Hat
security flaw
vendor_redhat·2002-12-19·CVSS 7.5
CVE-2002-1368 [HIGH] security flaw
security flaw
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
Debian
CVE-2002-1368: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...
vendor_debian·2002·CVSS 7.5
CVE-2002-1368 [HIGH] CVE-2002-1368: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed in 1.1.18-1)
trixie: resolved (fixed in 1.1.18-1)
No detection rules found.
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-004.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://secunia.com/advisories/7756/http://secunia.com/advisories/7794http://secunia.com/advisories/7803http://secunia.com/advisories/7843http://secunia.com/advisories/7858http://secunia.com/advisories/7907http://secunia.com/advisories/7913/http://secunia.com/advisories/8080/http://secunia.com/advisories/9325/http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6437https://exchange.xforce.ibmcloud.com/vulnerabilities/10909ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-004.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://secunia.com/advisories/7756/http://secunia.com/advisories/7794http://secunia.com/advisories/7803http://secunia.com/advisories/7843http://secunia.com/advisories/7858http://secunia.com/advisories/7907http://secunia.com/advisories/7913/http://secunia.com/advisories/8080/http://secunia.com/advisories/9325/http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6437https://exchange.xforce.ibmcloud.com/vulnerabilities/10909
2002-12-26
Published
Exploited in the wild