cbcvebase.
CVE-2007-5849
published 2007-12-19

CVE-2007-5849: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary…

PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
13.61%
96.0th percentile
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

Affected

10 ranges
VendorProductVersion rangeFixed in
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
debiancups< cups 1.3.5-1 (bookworm)cups 1.3.5-1 (bookworm)
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups

Detection & IOCsextracted from sources · hover to see the quote

port161/udp
pathbackend/snmp.c
bytes
\x30\x38\x02\x01\x00\x04\x84\xff\xff\xff\xff\x41\x41
  • Detect malformed SNMP responses with an ASN.1 community string length field set to 0xffffffff (integer underflow trigger). The crafted packet contains tag 0x04, followed by 0x84 0xff 0xff 0xff 0xff encoding a length of 4294967295.
  • Monitor for unexpected crashes or termination of the CUPS SNMP backend helper process (snmp backend), especially during printer auto-discovery events, as exploitation causes a stack-based buffer overflow in the SNMP helper.
  • The vulnerability is only triggerable when an administrator initiates an SNMP printer discovery scan; monitor for SNMP UDP traffic on port 161 with oversized or malformed community name length fields arriving during such events.
  • ·CUPS built with stack-protector support reduces exploitability to denial-of-service only (crash of the SNMP helper), preventing arbitrary code execution.
  • ·The SNMP backend is not present in RHEL releases earlier than 5; only RHEL 5 (and equivalent CUPS 1.2+) deployments are vulnerable.
  • ·The vulnerability is fixed in CUPS 1.3.5; systems running 1.3.5 or later are not affected.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.