CVE-2008-1373Improper Restriction of Operations within the Bounds of a Memory Buffer in Software Products Cups

Severity
5.8MEDIUMNVD
CNA2.6OSV2.6
EPSS
7.5%
top 8.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 1

Description

Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF file with a large code_size value, a similar issue to CVE-2006-4484.

CVSS vector

AV:A/AC:L/C:P/I:P/A:PExploitability: 6.5 | Impact: 6.4

Affected Packages2 packages

Debianapple/cups< 1.3.7-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4gx2-wfcv-mvp8: Buffer overflow in the gif_read_lzw function in CUPS 12022-05-01
OSV
CVE-2008-1373: Buffer overflow in the gif_read_lzw function in CUPS 12008-04-04
CVEList
CVE-2008-1373: Buffer overflow in the gif_read_lzw function in CUPS 12008-04-04

📋Vendor Advisories

3
Ubuntu
CUPS vulnerabilities2008-04-02
Red Hat
cups: overflow in gif image filter2008-04-01
Debian
CVE-2008-1373: cups - Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attacke...2008

💬Community

2
Bugzilla
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities2009-05-26
Bugzilla
CVE-2008-1373 cups: overflow in gif image filter2008-03-20
CVE-2008-1373 — Software Products Cups vulnerability | cvebase