CVE-2008-5286
published 2008-12-01CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.40%
90.3th percentile
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_ubuntu7.5HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2009-01-12·CVSS 7.5
CVE-2008-5183 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that CUPS didn't properly handle adding a large number of RSS
subscriptions. A local user could exploit this and cause CUPS to crash, leading
to a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and
8.10. (CVE-2008-5183)
It was discovered that CUPS did not authenticate users when adding and
cancelling RSS subscriptions. An unprivileged local user could bypass intended
restrictions and add a large number of RSS subscriptions. This issue only
applied to Ubuntu 7.10 and 8.04 LTS. (CVE-2008-5184)
It was discovered that the PNG filter in CUPS did not properly handle certain
malformed images. If a user or automated system were tricked into opening a
crafted PNG image file, a remote attacker could
Red Hat
cups: Incomplete fix for CVE-2008-1722
vendor_redhat·2008-10-16·CVSS 4.3
CVE-2008-5286 [MEDIUM] cups: Incomplete fix for CVE-2008-1722
cups: Incomplete fix for CVE-2008-1722
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
Debian
CVE-2008-5286: cups - Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 ...
vendor_debian·2008·CVSS 7.5
CVE-2008-5286 [HIGH] CVE-2008-5286: cups - Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 ...
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny4)
bullseye: resolved (fixed in 1.3.8-1lenny4)
forky: resolved (fixed in 1.3.8-1lenny4)
sid: resolved (fixed in 1.3.8-1lenny4)
trixie: resolved (fixed in 1.3.8-1lenny4)
GHSA
GHSA-wj8g-27x5-crw6: Integer overflow in the _cupsImageReadPNG function in CUPS 1
ghsa_unreviewed·2022-05-17
CVE-2008-5286 [HIGH] GHSA-wj8g-27x5-crw6: Integer overflow in the _cupsImageReadPNG function in CUPS 1
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
OSV
CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 1
osv·2008-12-01·CVSS 7.5
CVE-2008-5286 [HIGH] CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 1
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
No detection rules found.
No public exploits indexed.
Talos
Rule release for today
blogs_talos·2008-12-16·CVSS 5.0
CVE-2008-2595 [MEDIUM] Rule release for today
Today's VRT Certified Rule release has coverage for a vulnerability in Oracle Internet Directory and CUPS. There are also a few new rules added in chat.rules and others.
Oracle Internet Directory Denial of Service (CVE-2008-2595):
Oracle Internet Directory contains a programming error that may allow a remote attacker to cause a Denial of Service (DoS) against the application. This issue does not require authentication.
CUPS Integer Overflow (CVE-2008-5286):
A vulnerability in the _cupsImageReadPNG function in CUPS may allow a remote attacker to execute code on a vulnerable system.
Here's the link to today's release: http://www.snort.org/vrt/advisories/vrt-rules-2008-12-16.html
Talos
Rule release for today
blogs_talos·2008-12-16·CVSS 5.0
CVE-2008-2595 [MEDIUM] Rule release for today
## Rule release for today
Today's VRT Certified Rule release has coverage for a vulnerability in Oracle Internet Directory and CUPS. There are also a few new rules added in chat.rules and others.
Oracle Internet Directory Denial of Service (CVE-2008-2595): Oracle Internet Directory contains a programming error that may allow a remote attacker to cause a Denial of Service (DoS) against the application. This issue does not require authentication.
CUPS Integer Overflow (CVE-2008-5286): A vulnerability in the _cupsImageReadPNG function in CUPS may allow a remote attacker to execute code on a vulnerable system.
Here's the link to today's release: http://www.snort.org/vrt/advisories/vrt-rules-2008-12-16.html
Bugzilla
CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
bugzilla·2008-12-01·CVSS 4.3
CVE-2008-5286 [MEDIUM] CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722
Common Vulnerabilities and Exposures originally assigned an identifier CVE-2008-1722 to the following vulnerability:
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
It was discovered, the original patch for this issue was incomplete and
integer overflow in filter/image-png.c was still present. This could allow
an attacker to cause a denial of service (crash) via a crafted PNG image.
References:
http://svn.easysw.com/public/cups/trunk/CHANGES-1.3.txt
http://www.cups.org/str.php?L2974
Patch:
http://www.cups.org/strfiles/2974/str2974.patch
Discussion:
Description fro
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://secunia.com/advisories/32962http://secunia.com/advisories/33101http://secunia.com/advisories/33111http://secunia.com/advisories/33568http://svn.easysw.com/public/cups/trunk/CHANGES-1.3.txthttp://www.cups.org/str.php?L2974http://www.debian.org/security/2008/dsa-1677http://www.gentoo.org/security/en/glsa/glsa-200812-01.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:028http://www.mandriva.com/security/advisories?name=MDVSA-2009:029http://www.openwall.com/lists/oss-security/2008/12/01/1http://www.redhat.com/support/errata/RHSA-2008-1028.htmlhttp://www.securityfocus.com/bid/32518http://www.securitytracker.com/id?1021298http://www.vupen.com/english/advisories/2008/3315https://exchange.xforce.ibmcloud.com/vulnerabilities/46933https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10058http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://secunia.com/advisories/32962http://secunia.com/advisories/33101http://secunia.com/advisories/33111http://secunia.com/advisories/33568http://svn.easysw.com/public/cups/trunk/CHANGES-1.3.txthttp://www.cups.org/str.php?L2974http://www.debian.org/security/2008/dsa-1677http://www.gentoo.org/security/en/glsa/glsa-200812-01.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200812-11.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:028http://www.mandriva.com/security/advisories?name=MDVSA-2009:029http://www.openwall.com/lists/oss-security/2008/12/01/1http://www.redhat.com/support/errata/RHSA-2008-1028.htmlhttp://www.securityfocus.com/bid/32518http://www.securitytracker.com/id?1021298http://www.vupen.com/english/advisories/2008/3315https://exchange.xforce.ibmcloud.com/vulnerabilities/46933https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10058
2008-12-01
Published