CVE-2008-0882
published 2008-02-21CVE-2008-0882: Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.79%
92.3th percentile
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.6-1 | 1.3.6-1 |
| apple | cups | >= 0 < 1.3.6-1 | 1.3.6-1 |
| apple | cups | >= 0 < 1.3.6-1 | 1.3.6-1 |
| apple | cups | >= 0 < 1.3.6-1 | 1.3.6-1 |
| cups | cups | — | — |
| debian | cups | < cups 1.3.6-1 (bookworm) | cups 1.3.6-1 (bookworm) |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-04-02·CVSS 9.3
CVE-2008-0047 [CRITICAL] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the CUPS administration interface contained a heap-
based overflow flaw. A local attacker, and a remote attacker if printer
sharing is enabled, could send a malicious request and possibly execute
arbitrary code as the non-root user in Ubuntu 6.06 LTS, 6.10, and 7.04.
In Ubuntu 7.10, attackers would be isolated by the AppArmor CUPS profile.
(CVE-2008-0047)
It was discovered that the hpgl filter in CUPS did not properly validate
its input when parsing parameters. If a crafted HP-GL/2 file were printed,
an attacker could possibly execute arbitrary code as the non-root user
in Ubuntu 6.06 LTS, 6.10, and 7.04. In Ubuntu 7.10, attackers would be
isolated by the AppArmor CUPS profile. (CVE-2008-0053)
It was disco
Red Hat
cups: double free vulnerability in process_browse_data()
vendor_redhat·2008-01-07·CVSS 10.0
CVE-2008-0882 [CRITICAL] cups: double free vulnerability in process_browse_data()
cups: double free vulnerability in process_browse_data()
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
Debian
CVE-2008-0882: cups - Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allo...
vendor_debian·2008·CVSS 10.0
CVE-2008-0882 [CRITICAL] CVE-2008-0882: cups - Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allo...
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.3.6-1)
bullseye: resolved (fixed in 1.3.6-1)
forky: resolved (fixed in 1.3.6-1)
sid: resolved (fixed in 1.3.6-1)
trixie: resolved (fixed in 1.3.6-1)
GHSA
GHSA-vcjx-xf8c-qxqm: Double free vulnerability in the process_browse_data function in CUPS 1
ghsa_unreviewed·2022-05-01
CVE-2008-0882 [HIGH] CWE-119 GHSA-vcjx-xf8c-qxqm: Double free vulnerability in the process_browse_data function in CUPS 1
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
OSV
CVE-2008-0882: Double free vulnerability in the process_browse_data function in CUPS 1
osv·2008-02-21·CVSS 10.0
CVE-2008-0882 [CRITICAL] CVE-2008-0882: Double free vulnerability in the process_browse_data function in CUPS 1
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4069 Mozilla XBM decoder information disclosure
bugzilla·2008-09-22·CVSS 5.0
CVE-2008-4069 [MEDIUM] CVE-2008-4069 Mozilla XBM decoder information disclosure
CVE-2008-4069 Mozilla XBM decoder information disclosure
From MFSA 2008-45:
Security researcher Billy Hoffman discovered a bug in the XBM decoder that
allowed random small chunks of uninitialized memory to be read. The
severity of this bug was low and did not appear to cause any memory
corruption.
Discussion:
This is now public
---
This was addressed via:
Red Hat Enterprise Linux version 2.1 (RHSA-2008:0882)
Red Hat Enterprise Linux version 3 (RHSA-2008:0882)
Red Hat Enterprise Linux version 4 (RHSA-2008:0882)
Bugzilla
CVE-2008-0016 Mozilla UTF-8 stack buffer overflow
bugzilla·2008-09-22·CVSS 10.0
CVE-2008-0016 [CRITICAL] CVE-2008-0016 Mozilla UTF-8 stack buffer overflow
CVE-2008-0016 Mozilla UTF-8 stack buffer overflow
From MFSA 2008-37:
Justin Schuh and Tom Cross of the IBM X-Force and Peter Williams of IBM
Watson Labs reported errors in Mozilla URL parsing routines. These errors
could be exploited using a specially crafted UTF-8 URL in a hyperlink which
could overflow a stack buffer and allow an attacker to execute arbitrary
code.
Discussion:
This is now public
---
thunderbird-2.0.0.18-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
thunderbird-2.0.0.18-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This was addressed via:
Red Hat Enterprise Linux version 2.1 (RHSA-2008:0882)
Red
Bugzilla
CVE-2008-4067 Mozilla resource: traversal vulnerability
bugzilla·2008-09-22·CVSS 4.3
CVE-2008-4067 [MEDIUM] CVE-2008-4067 Mozilla resource: traversal vulnerability
CVE-2008-4067 Mozilla resource: traversal vulnerability
From MFSA 2008-44:
Mozilla developer Boris Zbarsky reported that the resource: protocol
allowed directory traversal on Linux when using URL-encoded slashes.
Discussion:
This is now public
---
thunderbird-2.0.0.18-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
thunderbird-2.0.0.18-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This was addressed via:
Red Hat Enterprise Linux version 4 (firefox) RHSA-2008:0879
Red Hat Enterprise Linux version 5 (firefox) RHSA-2008:0879
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2008:0882
Red Hat Enterprise Linux versi
Bugzilla
CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation
bugzilla·2008-09-22·CVSS 7.5
CVE-2008-3835 [HIGH] CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation
CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation
From MFSA 2008-38:
Mozilla security researcher moz_bug_r_a4 reported that the same-origin
check in nsXMLDocument::OnChannelRedirect() could be bypassed. This
vulnerability could be used to execute JavaScript in the context of a
different website.
Discussion:
This is now public
---
thunderbird-2.0.0.18-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
thunderbird-2.0.0.18-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This was addressed via:
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2008:0882
Red Hat Enterprise Linux version 3 (
Bugzilla
CVE-2008-3837 mozilla: Forced mouse drag
bugzilla·2008-09-22·CVSS 9.3
CVE-2008-3837 [CRITICAL] CVE-2008-3837 mozilla: Forced mouse drag
CVE-2008-3837 mozilla: Forced mouse drag
From MFSA 2008-40:
Mozilla developer Paul Nickerson reported a variant of a click-hijacking
vulnerability discovered in Internet Explorer by Liu Die Yu. The
vulnerability allowed an attacker to move the content window while the
mouse was being clicked, causing an item to be dragged rather than
clicked-on. This issue could potentially be used to force a user to
download a file or perform other drag-and-drop actions.
Discussion:
This is now public
---
This was addressed via:
Red Hat Enterprise Linux version 4 (firefox) RHSA-2008:0879
Red Hat Enterprise Linux version 5 (firefox) RHSA-2008:0879
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2008:0882
Red Hat Enterprise Linux version 3 (seamonkey) RHSA-2008:0882
Red Hat Enterprise Linux vers
Bugzilla
CVE-2008-0053 cups: buffer overflows in HP-GL/2 filter
bugzilla·2008-03-19·CVSS 10.0
CVE-2008-0053 [CRITICAL] CVE-2008-0053 cups: buffer overflows in HP-GL/2 filter
CVE-2008-0053 cups: buffer overflows in HP-GL/2 filter
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0053 to the following vulnerability:
Unspecified vulnerability in CUPS before 1.3.6 in Apple Mac OS X 10.5.2 has unknown impact and attack vectors related to "input validation."
References:
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
Discussion:
Listed in APPLE-SA-2008-03-18 along with CVE-2008-0882:
CUPS
CVE-ID: CVE-2008-0053, CVE-2008-0882
Available for: Mac OS X v10.5.2, Mac OS X Server v10.5.2
Impact: Multiple vulnerabilities in CUPS may lead to an unexpected
application termination or arbitrary code execution with system
privileges
Description: Multiple input validation issues exist in CUPS, the
most serious of which may lead to
Bugzilla
CVE-2008-0882 cups: double free vulnerability in process_browse_data()
bugzilla·2008-02-21·CVSS 10.0
CVE-2008-0882 [CRITICAL] CVE-2008-0882 cups: double free vulnerability in process_browse_data()
CVE-2008-0882 cups: double free vulnerability in process_browse_data()
Secunia has released and advisory affecting cups printing system:
http://secunia.com/advisories/28994/
Description:
A vulnerability has been discovered in CUPS, which can be exploited by
malicious people to cause a DoS (Denial of Service) or to potentially
compromise a vulnerable system.
The vulnerability is caused due to an error within the
"process_browse_data()" function when adding printers and classes. This
can be exploited to free the same buffer twice by sending specially
crafted browser packets to the UDP port on which cupsd is listening (by
default port 631/UDP).
Successful exploitation may allow execution of arbitrary code.
The vulnerability is confirmed in version 1.3.5. Prior versions may also
be affec
http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00000.htmlhttp://secunia.com/advisories/28994http://secunia.com/advisories/29067http://secunia.com/advisories/29120http://secunia.com/advisories/29132http://secunia.com/advisories/29251http://secunia.com/advisories/29420http://secunia.com/advisories/29485http://secunia.com/advisories/29603http://secunia.com/advisories/29634http://security.gentoo.org/glsa/glsa-200804-01.xmlhttp://www.cups.org/str.php?L2656http://www.debian.org/security/2008/dsa-1530http://www.mandriva.com/security/advisories?name=MDVSA-2008:050http://www.mandriva.com/security/advisories?name=MDVSA-2008:051http://www.redhat.com/support/errata/RHSA-2008-0157.htmlhttp://www.securityfocus.com/bid/27906http://www.securitytracker.com/id?1019473http://www.ubuntu.com/usn/usn-598-1http://www.vupen.com/english/advisories/2008/0623http://www.vupen.com/english/advisories/2008/0924/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=433758https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9625https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00792.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00832.htmlhttp://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00000.htmlhttp://secunia.com/advisories/28994http://secunia.com/advisories/29067http://secunia.com/advisories/29120http://secunia.com/advisories/29132http://secunia.com/advisories/29251http://secunia.com/advisories/29420http://secunia.com/advisories/29485http://secunia.com/advisories/29603http://secunia.com/advisories/29634http://security.gentoo.org/glsa/glsa-200804-01.xmlhttp://www.cups.org/str.php?L2656http://www.debian.org/security/2008/dsa-1530http://www.mandriva.com/security/advisories?name=MDVSA-2008:050http://www.mandriva.com/security/advisories?name=MDVSA-2008:051http://www.redhat.com/support/errata/RHSA-2008-0157.htmlhttp://www.securityfocus.com/bid/27906http://www.securitytracker.com/id?1019473http://www.ubuntu.com/usn/usn-598-1http://www.vupen.com/english/advisories/2008/0623http://www.vupen.com/english/advisories/2008/0924/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=433758https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9625https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00792.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00832.html
2008-02-21
Published