CVE-2008-3640
published 2008-10-14CVE-2008-3640: Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.65%
90.8th percentile
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.8 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjcq-j2gf-3gvx: Integer overflow in the WriteProlog function in texttops in CUPS 1
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-0577 [MEDIUM] GHSA-cjcq-j2gf-3gvx: Integer overflow in the WriteProlog function in texttops in CUPS 1
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
GHSA
GHSA-45qx-8jq2-whqw: Integer overflow in the WriteProlog function in texttops in CUPS before 1
ghsa_unreviewed·2022-05-02
CVE-2008-3640 [MEDIUM] GHSA-45qx-8jq2-whqw: Integer overflow in the WriteProlog function in texttops in CUPS before 1
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
OSV
CVE-2008-3640: Integer overflow in the WriteProlog function in texttops in CUPS before 1
osv·2008-10-14·CVSS 6.8
CVE-2008-3640 [MEDIUM] CVE-2008-3640: Integer overflow in the WriteProlog function in texttops in CUPS before 1
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
Red Hat
cups-CVE-2008-3640.patch has been corrupted.
vendor_redhat·2009-02-17·CVSS 6.8
CVE-2009-0577 [MEDIUM] cups-CVE-2008-3640.patch has been corrupted.
cups-CVE-2008-3640.patch has been corrupted.
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 4.3
CVE-2008-1722 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the SGI image filter in CUPS did not perform
proper bounds checking. If a user or automated system were tricked
into opening a crafted SGI image, an attacker could cause a denial
of service. (CVE-2008-3639)
It was discovered that the texttops filter in CUPS did not properly
validate page metrics. If a user or automated system were tricked into
opening a crafted text file, an attacker could cause a denial of
service. (CVE-2008-3640)
It was discovered that the HP-GL filter in CUPS did not properly check
for invalid pen parameters. If a user or automated system were tricked
into opening a crafted HP-GL or HP-GL/2 file, a remote attacker could
cause a denial of service or execute arbitrary code with user
privi
Red Hat
CUPS: texttops integer overflow
vendor_redhat·2008-10-09·CVSS 6.8
CVE-2008-3640 [MEDIUM] CWE-190 CUPS: texttops integer overflow
CUPS: texttops integer overflow
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
Debian
CVE-2008-3640: cups - Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 al...
vendor_debian·2008·CVSS 6.8
CVE-2008-3640 [MEDIUM] CVE-2008-3640: cups - Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 al...
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny2)
bullseye: resolved (fixed in 1.3.8-1lenny2)
forky: resolved (fixed in 1.3.8-1lenny2)
sid: resolved (fixed in 1.3.8-1lenny2)
trixie: resolved (fixed in 1.3.8-1lenny2)
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=752http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2919http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/bid/31690http://www.securitytracker.com/id?1021034http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568https://exchange.xforce.ibmcloud.com/vulnerabilities/45790https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10266https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=752http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2919http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/bid/31690http://www.securitytracker.com/id?1021034http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568https://exchange.xforce.ibmcloud.com/vulnerabilities/45790https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10266https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.html
2008-10-14
Published