CVE-2008-1374
published 2008-04-04CVE-2008-1374: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.87%
89.1th percentile
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.11 | — |
| debian | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
vendor_redhat·2008-04-01·CVSS 10.0
CVE-2008-1374 [CRITICAL] cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Debian
CVE-2008-1374: cups - Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, ...
vendor_debian·2008·CVSS 10.0
CVE-2008-1374 [CRITICAL] CVE-2008-1374: cups - Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, ...
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3qp4-8w7m-xx2g: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute a
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2008-1374 [CRITICAL] CWE-190 GHSA-3qp4-8w7m-xx2g: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute a
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
No detection rules found.
Bugzilla
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
bugzilla·2009-05-26·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #500493: CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
bug #500488: CVE-2009-1373 pidgin file transfer buffer overflow
bug #500490: CVE-2009-1374 pidgin DoS when decrypting qq packets
bug #500491: CVE-2009-1375 pidgin PurpleCircBuffer corruption
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE
Bugzilla
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
bugzilla·2008-03-20·CVSS 10.0
CVE-2008-1374 [CRITICAL] CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
It was discovered that patch applied to cups packages as shipped in Red Hat
Enterprise Linux 3 and 4 to address security issues in xpdf code known as
CVE-2004-0888 / CVE-2005-0206 was incomplete.
On certain platforms, malicious pdf file could still cause a crash or possibly
cause code execution when it's processed by pdftops filter.
This issue affects 64-bit platforms. cups packages in Red Hat Enterprise Linux
5 are not affected by this problem.
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0206.html
http://secunia.com/advisories/29630http://secunia.com/advisories/31388http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0245http://www.redhat.com/support/errata/RHSA-2008-0206.htmlhttp://www.securityfocus.com/archive/1/495164/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/41758https://issues.rpath.com/browse/RPL-2390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9636http://secunia.com/advisories/29630http://secunia.com/advisories/31388http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0245http://www.redhat.com/support/errata/RHSA-2008-0206.htmlhttp://www.securityfocus.com/archive/1/495164/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/41758https://issues.rpath.com/browse/RPL-2390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9636
2008-04-04
Published