CVE-2008-5286Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Cups

CWE-18910 documents9 sources
Severity
7.5HIGHNVD
EPSS
8.3%
top 7.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 1
Latest updateMay 17

Description

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianapple/cups< 1.3.8-1lenny4+3
NVDapple/cups32 versions+31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wj8g-27x5-crw6: Integer overflow in the _cupsImageReadPNG function in CUPS 12022-05-17
OSV
CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 12008-12-01
CVEList
CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 12008-12-01

📋Vendor Advisories

3
Ubuntu
CUPS vulnerabilities2009-01-12
Red Hat
cups: Incomplete fix for CVE-2008-17222008-10-16
Debian
CVE-2008-5286: cups - Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 ...2008

🕵️Threat Intelligence

2
Talos
Rule release for today2008-12-16
Talos
Rule release for today2008-12-16

💬Community

1
Bugzilla
CVE-2008-5286 cups: Incomplete fix for CVE-2008-17222008-12-01
CVE-2008-5286 — Apple Cups vulnerability | cvebase