CVE-2008-3641
published 2008-10-10CVE-2008-3641: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color…
PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
24.13%
97.6th percentile
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.8 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploit attempts by monitoring IPP (port 631) POST requests to /printers/ paths with Content-Type: application/ipp carrying document-format 'application/vnd.hp-HPGL', especially from User-Agent 'Internet Print Provider'. ↗
- →The exploit payload begins with the HP-GL/2 opcode 'BP;' (Begin Plot) which CUPS uses to recognize the file type; monitor HP-GL/2 jobs submitted over IPP for anomalous PW (pen width) and PC (pen color) opcode sequences that encode shellcode. ↗
- →The vulnerability resides in PW_pen_width() and PC_pen_color() functions in the hpgltops CUPS image filter; monitor for crashes or unexpected code execution originating from the hpgltops process. ↗
- →Successful remote exploitation requires printer sharing to be enabled; audit CUPS configurations for publicly shared printers as an attack surface reduction measure. ↗
- →The exploit targets CUPS versions prior to 1.3.9; identify vulnerable hosts by fingerprinting CUPS version strings on port 631. ↗
- ·The exploit hardcodes the Pens[] static buffer address and fprintf GOT address specific to a particular hpgltops binary build; these offsets will differ across distributions and compiler versions. ↗
- ·The exploit was developed and tested against linux 2.6.25 with randomize_va_space=1 and glibc 2.7; ASLR configurations or different kernel/libc versions may affect reliability. ↗
- ·On Ubuntu 7.10 and 8.04 LTS, exploitation impact is mitigated by the AppArmor CUPS profile which isolates the attacker. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 4.3
CVE-2008-1722 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the SGI image filter in CUPS did not perform
proper bounds checking. If a user or automated system were tricked
into opening a crafted SGI image, an attacker could cause a denial
of service. (CVE-2008-3639)
It was discovered that the texttops filter in CUPS did not properly
validate page metrics. If a user or automated system were tricked into
opening a crafted text file, an attacker could cause a denial of
service. (CVE-2008-3640)
It was discovered that the HP-GL filter in CUPS did not properly check
for invalid pen parameters. If a user or automated system were tricked
into opening a crafted HP-GL or HP-GL/2 file, a remote attacker could
cause a denial of service or execute arbitrary code with user
privi
Red Hat
CUPS: HP/GL reader insufficient bounds checking
vendor_redhat·2008-10-09·CVSS 10.0
CVE-2008-3641 [CRITICAL] CUPS: HP/GL reader insufficient bounds checking
CUPS: HP/GL reader insufficient bounds checking
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
Debian
CVE-2008-3641: cups - The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows ...
vendor_debian·2008·CVSS 10.0
CVE-2008-3641 [CRITICAL] CVE-2008-3641: cups - The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows ...
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny2)
bullseye: resolved (fixed in 1.3.8-1lenny2)
forky: resolved (fixed in 1.3.8-1lenny2)
sid: resolved (fixed in 1.3.8-1lenny2)
trixie: resolved (fixed in 1.3.8-1lenny2)
GHSA
GHSA-6fwg-7777-r73j: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1
ghsa_unreviewed·2022-05-02
CVE-2008-3641 [HIGH] GHSA-6fwg-7777-r73j: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
OSV
CVE-2008-3641: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1
osv·2008-10-10·CVSS 10.0
CVE-2008-3641 [CRITICAL] CVE-2008-3641: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
No detection rules found.
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32222http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://secunia.com/advisories/33568http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.apple.com/kb/HT3216http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2911http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/archive/1/497221/100/0/threadedhttp://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31688http://www.securitytracker.com/id?1021031http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568http://www.zerodayinitiative.com/advisories/ZDI-08-067https://exchange.xforce.ibmcloud.com/vulnerabilities/45779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9666https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.htmlhttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://secunia.com/advisories/32084http://secunia.com/advisories/32222http://secunia.com/advisories/32226http://secunia.com/advisories/32284http://secunia.com/advisories/32292http://secunia.com/advisories/32316http://secunia.com/advisories/32331http://secunia.com/advisories/33085http://secunia.com/advisories/33111http://secunia.com/advisories/33568http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1http://support.apple.com/kb/HT3216http://support.avaya.com/elmodocs2/security/ASA-2008-470.htmhttp://www.cups.org/articles.php?L575http://www.cups.org/str.php?L2911http://www.debian.org/security/2008/dsa-1656http://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:211http://www.redhat.com/support/errata/RHSA-2008-0937.htmlhttp://www.securityfocus.com/archive/1/497221/100/0/threadedhttp://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31688http://www.securitytracker.com/id?1021031http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2008/2782http://www.vupen.com/english/advisories/2008/3401http://www.vupen.com/english/advisories/2009/1568http://www.zerodayinitiative.com/advisories/ZDI-08-067https://exchange.xforce.ibmcloud.com/vulnerabilities/45779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9666https://usn.ubuntu.com/656-1/https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00331.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00380.html
2008-10-10
Published