CVE-2002-1384
published 2003-01-02CVE-2002-1384: Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace…
PriorityP420high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.69%
49.2th percentile
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| apple | cups | >= 0 < 1.1.18-1 | 1.1.18-1 |
| debian | cups | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| debian | xpdf | < cups 1.1.18-1 (bookworm) | cups 1.1.18-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9542-fgmx-fggg: Integer overflow in pdftops, as used in Xpdf 2
ghsa_unreviewed·2022-04-30
CVE-2002-1384 [HIGH] GHSA-9542-fgmx-fggg: Integer overflow in pdftops, as used in Xpdf 2
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
OSV
CVE-2002-1384: Integer overflow in pdftops, as used in Xpdf 2
osv·2003-01-02·CVSS 7.2
CVE-2002-1384 [HIGH] CVE-2002-1384: Integer overflow in pdftops, as used in Xpdf 2
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Red Hat
security flaw
vendor_redhat·2002-12-23·CVSS 7.2
CVE-2002-1384 [HIGH] security flaw
security flaw
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Debian
CVE-2002-1384: cups - Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS ...
vendor_debian·2002·CVSS 7.2
CVE-2002-1384 [HIGH] CVE-2002-1384: cups - Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS ...
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed in 1.1.18-1)
trixie: resolved (fixed in 1.1.18-1)
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=104152282309980&w=2http://www.debian.org/security/2003/dsa-222http://www.debian.org/security/2003/dsa-226http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.23.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:002http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.redhat.com/support/errata/RHSA-2002-307.htmlhttp://www.redhat.com/support/errata/RHSA-2003-037.htmlhttp://www.redhat.com/support/errata/RHSA-2003-216.htmlhttp://www.securityfocus.com/bid/6475https://exchange.xforce.ibmcloud.com/vulnerabilities/10937http://marc.info/?l=bugtraq&m=104152282309980&w=2http://www.debian.org/security/2003/dsa-222http://www.debian.org/security/2003/dsa-226http://www.debian.org/security/2003/dsa-232http://www.idefense.com/advisory/12.23.02.txthttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:002http://www.novell.com/linux/security/advisories/2003_002_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2002-295.htmlhttp://www.redhat.com/support/errata/RHSA-2002-307.htmlhttp://www.redhat.com/support/errata/RHSA-2003-037.htmlhttp://www.redhat.com/support/errata/RHSA-2003-216.htmlhttp://www.securityfocus.com/bid/6475https://exchange.xforce.ibmcloud.com/vulnerabilities/10937
2003-01-02
Published