CVE-2008-1722
published 2008-04-10CVE-2008-1722: Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.00%
78.7th percentile
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.7-2 | 1.3.7-2 |
| apple | cups | >= 0 < 1.3.7-2 | 1.3.7-2 |
| apple | cups | >= 0 < 1.3.7-2 | 1.3.7-2 |
| apple | cups | >= 0 < 1.3.7-2 | 1.3.7-2 |
| cups | cups | — | — |
| debian | cups | < cups 1.3.7-2 (bookworm) | cups 1.3.7-2 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups: Incomplete fix for CVE-2008-1722
vendor_redhat·2008-10-16·CVSS 4.3
CVE-2008-5286 [MEDIUM] cups: Incomplete fix for CVE-2008-1722
cups: Incomplete fix for CVE-2008-1722
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 4.3
CVE-2008-1722 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the SGI image filter in CUPS did not perform
proper bounds checking. If a user or automated system were tricked
into opening a crafted SGI image, an attacker could cause a denial
of service. (CVE-2008-3639)
It was discovered that the texttops filter in CUPS did not properly
validate page metrics. If a user or automated system were tricked into
opening a crafted text file, an attacker could cause a denial of
service. (CVE-2008-3640)
It was discovered that the HP-GL filter in CUPS did not properly check
for invalid pen parameters. If a user or automated system were tricked
into opening a crafted HP-GL or HP-GL/2 file, a remote attacker could
cause a denial of service or execute arbitrary code with user
privi
Ubuntu
CUPS vulnerability
vendor_ubuntu·2008-05-05·CVSS 4.3
CVE-2008-1722 [MEDIUM] CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS vulnerability
Thomas Pollet discovered that CUPS did not properly validate the size of
PNG images. A local attacker, and a remote attacker if printer sharing
is enabled, could send a crafted file and cause a denial of service or
possibly execute arbitrary code as the non-root user in Ubuntu 6.06 LTS
and 7.04. In Ubuntu 7.10, attackers would be isolated by the AppArmor
CUPS profile. (CVE-2008-1722)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
cups: integer overflow in the image filter
vendor_redhat·2008-04-08·CVSS 4.3
CVE-2008-1722 [MEDIUM] CWE-190 cups: integer overflow in the image filter
cups: integer overflow in the image filter
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
Debian
CVE-2008-1722: cups - Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c...
vendor_debian·2008·CVSS 4.3
CVE-2008-1722 [MEDIUM] CVE-2008-1722: cups - Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c...
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
Scope: local
bookworm: resolved (fixed in 1.3.7-2)
bullseye: resolved (fixed in 1.3.7-2)
forky: resolved (fixed in 1.3.7-2)
sid: resolved (fixed in 1.3.7-2)
trixie: resolved (fixed in 1.3.7-2)
GHSA
GHSA-v23p-4xpj-h834: Multiple integer overflows in (1) filter/image-png
ghsa_unreviewed·2022-05-01
CVE-2008-1722 [MEDIUM] CWE-20 GHSA-v23p-4xpj-h834: Multiple integer overflows in (1) filter/image-png
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
OSV
CVE-2008-1722: Multiple integer overflows in (1) filter/image-png
osv·2008-04-10·CVSS 4.3
CVE-2008-1722 [MEDIUM] CVE-2008-1722: Multiple integer overflows in (1) filter/image-png
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
bugzilla·2008-12-01·CVSS 4.3
CVE-2008-5286 [MEDIUM] CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
Common Vulnerabilities and Exposures originally assigned an identifier CVE-2008-1722 to the following vulnerability:
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
It was discovered, the original patch for this issue was incomplete and
integer overflow in filter/image-png.c was still present. This could allow
an attacker to cause a denial of service (crash) via a crafted PNG image.
References:
http://svn.easysw.com/public/cups/trunk/CHANGES-1.3.txt
http://www.cups.org/str.php?L2974
Patch:
http://www.cups.org/strfiles/2974/str2974.patch
Discussion:
Description fro
Bugzilla
CVE-2008-1722 cups: integer overflow in the image filter
bugzilla·2008-04-09·CVSS 4.3
CVE-2008-1722 [MEDIUM] CVE-2008-1722 cups: integer overflow in the image filter
CVE-2008-1722 cups: integer overflow in the image filter
Thomas Pollet reported an integer overflows leading to a heap overflow in the
CUPS' image filter:
http://www.cups.org/str.php?L2790
filter/image-png.c:
img->xsize * img->ysize may overflow (CUPS_IMAGE_MAX_WIDTH and
CUPS_IMAGE_MAX_HEIGHT are too big for multiplication).
malloc(img->xsize * img->ysize * 3) can result in a buffer that's too small.
Upstream patch: http://www.cups.org/strfiles/2790/str2790.patch
Discussion:
CVE-2008-1722:
Multiple integer overflows in (1) filter/image-png.c and (2)
filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of
service (crash) and trigger memory corruption, as demonstrated via a
crafted PNG image.
---
This issue affects Red Hat Enterprise Linux 3, 4, and 5.
---
As for ve
http://secunia.com/advisories/29809http://secunia.com/advisories/29902http://secunia.com/advisories/30078http://secunia.com/advisories/30190http://secunia.com/advisories/30553http://secunia.com/advisories/30717http://secunia.com/advisories/31324http://secunia.com/advisories/32292http://www.cups.org/str.php?L2790http://www.debian.org/security/2008/dsa-1625http://www.gentoo.org/security/en/glsa/glsa-200804-23.xmlhttp://www.kb.cert.org/vuls/id/218395http://www.mandriva.com/security/advisories?name=MDVSA-2008:170http://www.novell.com/linux/security/advisories/2008_13_sr.htmlhttp://www.osvdb.org/44398http://www.securityfocus.com/bid/28781http://www.securitytracker.com/id?1019854http://www.ubuntu.com/usn/usn-606-1http://www.vupen.com/english/advisories/2008/1226/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41832https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8768https://rhn.redhat.com/errata/RHSA-2008-0498.htmlhttps://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00068.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00081.htmlhttp://secunia.com/advisories/29809http://secunia.com/advisories/29902http://secunia.com/advisories/30078http://secunia.com/advisories/30190http://secunia.com/advisories/30553http://secunia.com/advisories/30717http://secunia.com/advisories/31324http://secunia.com/advisories/32292http://www.cups.org/str.php?L2790http://www.debian.org/security/2008/dsa-1625http://www.gentoo.org/security/en/glsa/glsa-200804-23.xmlhttp://www.kb.cert.org/vuls/id/218395http://www.mandriva.com/security/advisories?name=MDVSA-2008:170http://www.novell.com/linux/security/advisories/2008_13_sr.htmlhttp://www.osvdb.org/44398http://www.securityfocus.com/bid/28781http://www.securitytracker.com/id?1019854http://www.ubuntu.com/usn/usn-606-1http://www.vupen.com/english/advisories/2008/1226/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41832https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8768https://rhn.redhat.com/errata/RHSA-2008-0498.htmlhttps://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00068.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00081.html
2008-04-10
Published