CVE-2007-5849
published 2007-12-19CVE-2007-5849: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary…
PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
13.61%
96.0th percentile
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| debian | cups | < cups 1.3.5-1 (bookworm) | cups 1.3.5-1 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x30\x38\x02\x01\x00\x04\x84\xff\xff\xff\xff\x41\x41
- →Detect malformed SNMP responses with an ASN.1 community string length field set to 0xffffffff (integer underflow trigger). The crafted packet contains tag 0x04, followed by 0x84 0xff 0xff 0xff 0xff encoding a length of 4294967295. ↗
- →Monitor for unexpected crashes or termination of the CUPS SNMP backend helper process (snmp backend), especially during printer auto-discovery events, as exploitation causes a stack-based buffer overflow in the SNMP helper. ↗
- →The vulnerability is only triggerable when an administrator initiates an SNMP printer discovery scan; monitor for SNMP UDP traffic on port 161 with oversized or malformed community name length fields arriving during such events. ↗
- ·CUPS built with stack-protector support reduces exploitability to denial-of-service only (crash of the SNMP helper), preventing arbitrary code execution. ↗
- ·The SNMP backend is not present in RHEL releases earlier than 5; only RHEL 5 (and equivalent CUPS 1.2+) deployments are vulnerable. ↗
- ·The vulnerability is fixed in CUPS 1.3.5; systems running 1.3.5 or later are not affected. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-01-09
CVE-2007-5849 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
Wei Wang discovered that the SNMP discovery backend did not
correctly calculate the length of strings. If a user were tricked into
scanning for printers, a remote attacker could send a specially crafted
packet and possibly execute arbitrary code.
Elias Pipping discovered that temporary files were not handled safely
in certain situations when converting PDF to PS. A local attacker could
cause a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
CUPS SNMP backend buffer overflow
vendor_redhat·2007-12-13·CVSS 9.3
CVE-2007-5849 [CRITICAL] CUPS SNMP backend buffer overflow
CUPS SNMP backend buffer overflow
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
Statement: Not vulnerable.
This flaw does not affect the version of CUPS shipped in Red Hat Enterprise Linux 3 or 4.
After a detailed analysis of this flaw, it has been determined it does not pose a security threat on Red Hat Enterprise Linux 5. For more details regarding this analysis, please see:
https://bugzilla.redhat.com/show_bug.cgi?id=415131
Debian
CVE-2007-5849: cups - Integer underflow in the asn1_get_string function in the SNMP back end (backend/...
vendor_debian·2007·CVSS 9.3
CVE-2007-5849 [CRITICAL] CVE-2007-5849: cups - Integer underflow in the asn1_get_string function in the SNMP back end (backend/...
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.5-1)
bullseye: resolved (fixed in 1.3.5-1)
forky: resolved (fixed in 1.3.5-1)
sid: resolved (fixed in 1.3.5-1)
trixie: resolved (fixed in 1.3.5-1)
GHSA
GHSA-x2h6-2q5c-v7px: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp
ghsa_unreviewed·2022-05-01
CVE-2007-5849 [HIGH] GHSA-x2h6-2q5c-v7px: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
OSV
CVE-2007-5849: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp
osv·2007-12-19·CVSS 9.3
CVE-2007-5849 [CRITICAL] CVE-2007-5849: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
No detection rules found.
http://bugs.gentoo.org/show_bug.cgi?id=201570http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00003.htmlhttp://secunia.com/advisories/28113http://secunia.com/advisories/28129http://secunia.com/advisories/28136http://secunia.com/advisories/28200http://secunia.com/advisories/28386http://secunia.com/advisories/28441http://secunia.com/advisories/28636http://secunia.com/advisories/28676http://www.cups.org/str.php?L2589http://www.debian.org/security/2007/dsa-1437http://www.gentoo.org/security/en/glsa/glsa-200712-14.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:036http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/bid/26910http://www.securityfocus.com/bid/26917http://www.ubuntu.com/usn/usn-563-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2007/4242https://exchange.xforce.ibmcloud.com/vulnerabilities/39097https://exchange.xforce.ibmcloud.com/vulnerabilities/39101https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00908.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=201570http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00003.htmlhttp://secunia.com/advisories/28113http://secunia.com/advisories/28129http://secunia.com/advisories/28136http://secunia.com/advisories/28200http://secunia.com/advisories/28386http://secunia.com/advisories/28441http://secunia.com/advisories/28636http://secunia.com/advisories/28676http://www.cups.org/str.php?L2589http://www.debian.org/security/2007/dsa-1437http://www.gentoo.org/security/en/glsa/glsa-200712-14.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:036http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/bid/26910http://www.securityfocus.com/bid/26917http://www.ubuntu.com/usn/usn-563-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2007/4242https://exchange.xforce.ibmcloud.com/vulnerabilities/39097https://exchange.xforce.ibmcloud.com/vulnerabilities/39101https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00908.html
2007-12-19
Published