CVE-2002-1383Software Products Cups vulnerability

7 documents7 sources
Severity
10.0CRITICALNVD
EPSS
16.2%
top 5.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26
Latest updateMay 3

Description

Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

Debianapple/cups< 1.1.18-1+3
NVDeasy_software_products/cups13 versions+12
NVDapple/mac_os_x10.2, 10.2.2+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m243-hvg9-qc96: Multiple integer overflows in Common Unix Printing System (CUPS) 12022-05-03
OSV
CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 12002-12-26
CVEList
CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 12002-12-20

📋Vendor Advisories

2
Red Hat
security flaw2002-12-19
Debian
CVE-2002-1383: cups - Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through ...2002

💬Community

1
Bugzilla
CVE-2002-1383 security flaw2018-08-16
CVE-2002-1383 — Software Products Cups vulnerability | cvebase