CVE-2002-1371
published 2002-12-26CVE-2002-1371: filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.92%
91.2th percentile
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| debian | cups | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v85m-c74w-mhg8: filters/image-gif
ghsa_unreviewed·2022-04-30
CVE-2002-1371 [HIGH] GHSA-v85m-c74w-mhg8: filters/image-gif
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
OSV
CVE-2002-1371: filters/image-gif
osv·2002-12-26·CVSS 7.5
CVE-2002-1371 [HIGH] CVE-2002-1371: filters/image-gif
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
Red Hat
security flaw
vendor_redhat·2002-12-19·CVSS 7.5
CVE-2002-1371 [HIGH] security flaw
security flaw
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
Debian
CVE-2002-1371: cups - filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 ...
vendor_debian·2002·CVSS 7.5
CVE-2002-1371 [HIGH] CVE-2002-1371: cups - filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 ...
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed in 1.1.18-1)
trixie: resolved (fixed in 1.1.18-1)
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6439https://exchange.xforce.ibmcloud.com/vulnerabilities/10911http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702http://marc.info/?l=bugtraq&m=104032149026670&w=2http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.19.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.securityfocus.com/bid/6439https://exchange.xforce.ibmcloud.com/vulnerabilities/10911
2002-12-26
Published