CVE-2004-1267
published 2005-01-10CVE-2004-1267: Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a…
PriorityP431medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EXPLOIT
EPSS
6.25%
92.8th percentile
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| debian | cups | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3352-53wf-rvq5: Buffer overflow in the ParseCommand function in hpgl-input
ghsa_unreviewed·2022-04-29
CVE-2004-1267 [MEDIUM] CWE-119 GHSA-3352-53wf-rvq5: Buffer overflow in the ParseCommand function in hpgl-input
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
OSV
CVE-2004-1267: Buffer overflow in the ParseCommand function in hpgl-input
osv·2005-01-10·CVSS 6.5
CVE-2004-1267 [MEDIUM] CVE-2004-1267: Buffer overflow in the ParseCommand function in hpgl-input
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
CAN-2004-1125:
The recent USN-48-1 fixed a buffer overflow in xpdf. Since CUPS
contains xpdf code to convert incoming PDF files to the PostScript
format, this vulnerability applies to cups as well.
In this case it could even lead to privilege escalation: if an
attacker submitted a malicious PDF file for printing, he could be
able to execute arbitrary commands with the privileges of the
CUPS server.
Please note that the Ubuntu version of CUPS runs as a minimally
privileged user 'cupsys' by default, so there is no possibility of
root privilege escalation. The privileges of the 'cupsys' user are
confined to modifying printer configurations, altering print jobs,
and controlling printers.
CAN-2004-1267:
Ariel Berkman discovered a
Red Hat
security flaw
vendor_redhat·2004-12-15·CVSS 6.5
CVE-2004-1267 [MEDIUM] security flaw
security flaw
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Debian
CVE-2004-1267: cups - Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops pro...
vendor_debian·2004·CVSS 6.5
CVE-2004-1267 [MEDIUM] CVE-2004-1267: cups - Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops pro...
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fixed in 1.1.22-2)
No detection rules found.
http://tigger.uic.edu/~jlongs2/holes/cups.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18604https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10620https://usn.ubuntu.com/50-1/http://tigger.uic.edu/~jlongs2/holes/cups.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18604https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10620https://usn.ubuntu.com/50-1/
2005-01-10
Published