Description
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-r79v-84jh-ff36: Off-by-one error in the ippReadIO function in cups/ipp↗2022-05-01 ▶ OSVCVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp↗2007-10-31 ▶ CVEListCVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp↗2007-10-31 ▶ 📋Vendor Advisories
4UbuntuCUPS vulnerability↗2007-11-06 ▶ Red Hatcups boundary error↗2007-10-31 ▶ CiscoCommon UNIX Printing System IPP Tags Memory Corruption Vulnerability↗2007-10-31 ▶ DebianCVE-2007-4351: cups - Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows re...↗2007 ▶ 💬Community
5BugzillaCVE-2007-4351 cups boundary error [F7]↗2007-11-01 ▶ BugzillaCVE-2007-4351 cups boundary error [Fdevel]↗2007-11-01 ▶ BugzillaCVE-2007-4351 cups boundary error [FC6]↗2007-11-01 ▶ BugzillaCVE-2007-4351 cups boundary error [F8]↗2007-11-01 ▶ BugzillaCVE-2007-4351 cups boundary error↗2007-10-22 ▶