CVE-2008-3639
published 2008-10-14CVE-2008-3639: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.40%
90.3th percentile
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.8 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phmm-796g-q6c9: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1
ghsa_unreviewed·2022-05-02
CVE-2008-3639 [HIGH] CWE-119 GHSA-phmm-796g-q6c9: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
OSV
CVE-2008-3639: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1
osv·2008-10-14·CVSS 7.5
CVE-2008-3639 [HIGH] CVE-2008-3639: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 4.3
CVE-2008-1722 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the SGI image filter in CUPS did not perform
proper bounds checking. If a user or automated system were tricked
into opening a crafted SGI image, an attacker could cause a denial
of service. (CVE-2008-3639)
It was discovered that the texttops filter in CUPS did not properly
validate page metrics. If a user or automated system were tricked into
opening a crafted text file, an attacker could cause a denial of
service. (CVE-2008-3640)
It was discovered that the HP-GL filter in CUPS did not properly check
for invalid pen parameters. If a user or automated system were tricked
into opening a crafted HP-GL or HP-GL/2 file, a remote attacker could
cause a denial of service or execute arbitrary code with user
privi
Red Hat
CUPS: SGI image parser heap-based buffer overflow
vendor_redhat·2008-10-09·CVSS 7.5
CVE-2008-3639 [HIGH] CWE-122 CUPS: SGI image parser heap-based buffer overflow
CUPS: SGI image parser heap-based buffer overflow
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Debian
CVE-2008-3639: cups - Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS befor...
vendor_debian·2008·CVSS 7.5
CVE-2008-3639 [HIGH] CVE-2008-3639: cups - Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS befor...
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny2)
bullseye: resolved (fixed in 1.3.8-1lenny2)
forky: resolved (fixed in 1.3.8-1lenny2)
sid: resolved (fixed in 1.3.8-1lenny2)
trixie: resolved (fixed in 1.3.8-1lenny2)
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=753http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2918http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/bid/31690http://www.securitytracker.com/id?1021033http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568https://exchange.xforce.ibmcloud.com/vulnerabilities/45789https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11464https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=753http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2918http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/bid/31690http://www.securitytracker.com/id?1021033http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568https://exchange.xforce.ibmcloud.com/vulnerabilities/45789https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11464https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.html
2008-10-14
Published