CVE-2007-4351
published 2007-10-31CVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1)…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.38%
93.8th percentile
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.4-1 | 1.3.4-1 |
| apple | cups | >= 0 < 1.3.4-1 | 1.3.4-1 |
| apple | cups | >= 0 < 1.3.4-1 | 1.3.4-1 |
| apple | cups | >= 0 < 1.3.4-1 | 1.3.4-1 |
| cups | cups | <= 1.3.3 | — |
| debian | cups | < cups 1.3.4-1 (bookworm) | cups 1.3.4-1 (bookworm) |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r79v-84jh-ff36: Off-by-one error in the ippReadIO function in cups/ipp
ghsa_unreviewed·2022-05-01
CVE-2007-4351 [HIGH] GHSA-r79v-84jh-ff36: Off-by-one error in the ippReadIO function in cups/ipp
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
OSV
CVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp
osv·2007-10-31·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Cisco
Wide Area Application Services (WAAS) Common UNIX Printing System (CUPS) Vulnerability
vendor_cisco·2008-06-25
Wide Area Application Services (WAAS) Common UNIX Printing System (CUPS) Vulnerability
Wide Area Application Services (WAAS) Common UNIX Printing System (CUPS) Vulnerability
This is the Cisco PSIRT response to a security advisory regarding a
vulnerability in Common UNIX Printing System (CUPS). The CUPS security advisory
can be found at http://www.cups.org/str.php?L2561.
The Cisco Wide Area Application Services (WAAS) incorporates a print
server based on the integration of open source CUPS technology, which is
affected by this CUPS vulnerability.
This vulnerability can be remotely exploited and could result in
execution of arbitrary code on the Cisco WAAS products.
Additional Information
CSCsl92095 - Missing IPP value length range checks (STR #2561)
This vulnerability is referenced by CUPS as STR #2561. This CUPS
vulnerability is caused by a boundary error in the "ippReadIO
Ubuntu
CUPS vulnerability
vendor_ubuntu·2007-11-06
CVE-2007-4351 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS vulnerability
Alin Rad Pop discovered that CUPS did not correctly validate buffer
lengths when processing IPP tags. Remote attackers successfully
exploiting this vulnerability would gain access to the non-root CUPS user
in Ubuntu 6.06 LTS, 6.10, and 7.04. In Ubuntu 7.10, attackers would be
isolated by the AppArmor CUPS profile.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
cups boundary error
vendor_redhat·2007-10-31·CVSS 10.0
CVE-2007-4351 [CRITICAL] cups boundary error
cups boundary error
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Statement: Vulnerable. This issue affected the CUPS packages in Red Hat Enterprise Linux 5.
This issue also affected the versions of CUPS packages in Red Hat Enterprise Linux 3 and 4, but exploitation would only lead to a possible denial of service.
Cisco
Common UNIX Printing System IPP Tags Memory Corruption Vulnerability
vendor_cisco·2007-10-31·CVSS 10.0
CVE-2007-4351 [CRITICAL] CWE-94 Common UNIX Printing System IPP Tags Memory Corruption Vulnerability
Common UNIX Printing System IPP Tags Memory Corruption Vulnerability
The Common UNIX Printing System (CUPS) versions 1.3.3 and prior contain a vulnerability that can allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or execute arbitrary code with the privileges of the user.
The vulnerability exists in the ippReadIO() function when processing Internet Printing Protocol (IPP) tags. The function causes an off-by-one error when allocating space. An unauthenticated, remote attacker could send a request with crafted tags to overwrite one byte on the stack with a zero. The attacker could crash the daemon or possibly execute arbitrary code.
The vendor has confirmed this vulnerability in release notes and released an updated version.
The vulnerability requir
Debian
CVE-2007-4351: cups - Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows re...
vendor_debian·2007·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351: cups - Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows re...
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.4-1)
bullseye: resolved (fixed in 1.3.4-1)
forky: resolved (fixed in 1.3.4-1)
sid: resolved (fixed in 1.3.4-1)
trixie: resolved (fixed in 1.3.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4351 cups boundary error [F7]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351 cups boundary error [F7]
CVE-2007-4351 cups boundary error [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
cups-1.2.12-6.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-4351 cups boundary error [Fdevel]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351 cups boundary error [Fdevel]
CVE-2007-4351 cups boundary error [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I shamelessly dare to close as I see fix in devel. For F8 use #362971.
Bugzilla
CVE-2007-4351 cups boundary error [FC6]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351 cups boundary error [FC6]
CVE-2007-4351 cups boundary error [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Ping on this. Is it possible to get Fedora 6 updated?
---
This was FEDORA-2007-740, filed on the 1st of November and pushed on the 5th of
November (cups-1.2.12-5.fc6).
http://lwn.net/Articles/257286/
Bugzilla
CVE-2007-4351 cups boundary error [F8]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351 cups boundary error [F8]
CVE-2007-4351 cups boundary error [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This one is to track the flaw for F8. It is an F8 target, but I still don't see
it tagged and an I have no idea if an exception was granted. Will this make it
to GA, or will it go out as an update?
---
It will go out as an update (cups-1.3.4-1.fc8).
---
cups-1.3.4-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-4351 cups boundary error
bugzilla·2007-10-22·CVSS 10.0
CVE-2007-4351 [CRITICAL] CVE-2007-4351 cups boundary error
CVE-2007-4351 cups boundary error
Alin Rad Pop of the Secunia Research has discovered a vulnerability in CUPS,
which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the
"ippReadIO()" function in cups/ipp.c when processing IPP (Internet
Printing Protocol) tags. This can be exploited to overwrite one byte on
the stack with a zero by sending an IPP request containing specially
crafted "textWithLanguage" or "nameWithLanguage" tags.
Successful exploitation allows execution of arbitrary code.
Acknowledgements:
Red Hat would like to thank Alin Rad Pop for reporting this issue.
Discussion:
Created attachment 234891
Patch for CUPS 1.1 by Michael Sweet
---
Created attachment 234901
Patch for CUPS 1.2 by Micha
http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://secunia.com/advisories/27233http://secunia.com/advisories/27410http://secunia.com/advisories/27445http://secunia.com/advisories/27447http://secunia.com/advisories/27474http://secunia.com/advisories/27494http://secunia.com/advisories/27499http://secunia.com/advisories/27540http://secunia.com/advisories/27577http://secunia.com/advisories/27604http://secunia.com/advisories/27712http://secunia.com/advisories/28136http://secunia.com/advisories/30847http://secunia.com/secunia_research/2007-76/advisory/http://security.gentoo.org/glsa/glsa-200711-16.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.501902http://support.avaya.com/elmodocs2/security/ASA-2007-476.htmhttp://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.htmlhttp://www.cups.org/str.php?L2561http://www.debian.org/security/2007/dsa-1407http://www.kb.cert.org/vuls/id/446897http://www.mandriva.com/security/advisories?name=MDKSA-2007:204http://www.novell.com/linux/security/advisories/2007_58_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1020.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1022.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1023.htmlhttp://www.securityfocus.com/bid/26268http://www.securitytracker.com/id?1018879http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/3681http://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2008/1934/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=361661https://exchange.xforce.ibmcloud.com/vulnerabilities/38190https://issues.rpath.com/browse/RPL-1875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10604https://usn.ubuntu.com/539-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00012.htmlhttp://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://secunia.com/advisories/27233http://secunia.com/advisories/27410http://secunia.com/advisories/27445http://secunia.com/advisories/27447http://secunia.com/advisories/27474http://secunia.com/advisories/27494http://secunia.com/advisories/27499http://secunia.com/advisories/27540http://secunia.com/advisories/27577http://secunia.com/advisories/27604http://secunia.com/advisories/27712http://secunia.com/advisories/28136http://secunia.com/advisories/30847http://secunia.com/secunia_research/2007-76/advisory/http://security.gentoo.org/glsa/glsa-200711-16.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.501902http://support.avaya.com/elmodocs2/security/ASA-2007-476.htmhttp://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.htmlhttp://www.cups.org/str.php?L2561http://www.debian.org/security/2007/dsa-1407http://www.kb.cert.org/vuls/id/446897http://www.mandriva.com/security/advisories?name=MDKSA-2007:204http://www.novell.com/linux/security/advisories/2007_58_cups.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1020.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1022.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1023.htmlhttp://www.securityfocus.com/bid/26268http://www.securitytracker.com/id?1018879http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/3681http://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2008/1934/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=361661https://exchange.xforce.ibmcloud.com/vulnerabilities/38190https://issues.rpath.com/browse/RPL-1875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10604https://usn.ubuntu.com/539-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00012.html
2007-10-31
Published