CVE-2002-1383
published 2002-12-26CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.06%
94.7th percentile
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| debian | cups | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m243-hvg9-qc96: Multiple integer overflows in Common Unix Printing System (CUPS) 1
ghsa_unreviewed·2022-05-03
CVE-2002-1383 [HIGH] GHSA-m243-hvg9-qc96: Multiple integer overflows in Common Unix Printing System (CUPS) 1
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
OSV
CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1
osv·2002-12-26·CVSS 10.0
CVE-2002-1383 [CRITICAL] CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
Red Hat
security flaw
vendor_redhat·2002-12-19·CVSS 10.0
CVE-2002-1383 [CRITICAL] security flaw
security flaw
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
Debian
CVE-2002-1383: cups - Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through ...
vendor_debian·2002·CVSS 10.0
CVE-2002-1383 [CRITICAL] CVE-2002-1383: cups - Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through ...
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed in 1.1.18-1)
trixie: resolved (fixed in 1.1.18-1)
No detection rules found.
No public exploits indexed.
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-004.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://marc.info/?l=bugtraq&m=104032149026670&w=2http://secunia.com/advisories/7756/http://secunia.com/advisories/7794http://secunia.com/advisories/7803http://secunia.com/advisories/7843http://secunia.com/advisories/7858http://secunia.com/advisories/7907http://secunia.com/advisories/7913/http://secunia.com/advisories/8080/http://secunia.com/advisories/9325/http://www.idefense.com/advisory/12.19.02.txthttp://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-004.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.htmlhttp://marc.info/?l=bugtraq&m=104032149026670&w=2http://secunia.com/advisories/7756/http://secunia.com/advisories/7794http://secunia.com/advisories/7803http://secunia.com/advisories/7843http://secunia.com/advisories/7858http://secunia.com/advisories/7907http://secunia.com/advisories/7913/http://secunia.com/advisories/8080/http://secunia.com/advisories/9325/http://www.idefense.com/advisory/12.19.02.txthttp://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.html
2002-12-26
Published