CVE-2008-5377
published 2008-12-08CVE-2008-5377: pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability…
PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
0.72%
50.0th percentile
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
| apple | cups | >= 0 < 1.3.8-1lenny1 | 1.3.8-1lenny1 |
| apple | cups | >= 0 < 1.3.8-1lenny1 | 1.3.8-1lenny1 |
| apple | cups | >= 0 < 1.3.8-1lenny1 | 1.3.8-1lenny1 |
| apple | cups | >= 0 < 1.3.8-1lenny1 | 1.3.8-1lenny1 |
| debian | cups | < cups 1.3.8-1lenny1 (bookworm) | cups 1.3.8-1lenny1 (bookworm) |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv1.2LOW
vendor_ubuntu7.5HIGH
vendor_debian1.2LOW
vendor_redhat1.2LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fjp-m2ph-c7hw: pstopdf in CUPS 1
ghsa_unreviewed·2022-05-17·CVSS 1.2
CVE-2008-5377 [LOW] CWE-59 GHSA-4fjp-m2ph-c7hw: pstopdf in CUPS 1
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
OSV
CVE-2008-5377: pstopdf in CUPS 1
osv·2008-12-08·CVSS 1.2
CVE-2008-5377 [LOW] CVE-2008-5377: pstopdf in CUPS 1
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2009-01-12·CVSS 7.5
CVE-2008-5183 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that CUPS didn't properly handle adding a large number of RSS
subscriptions. A local user could exploit this and cause CUPS to crash, leading
to a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and
8.10. (CVE-2008-5183)
It was discovered that CUPS did not authenticate users when adding and
cancelling RSS subscriptions. An unprivileged local user could bypass intended
restrictions and add a large number of RSS subscriptions. This issue only
applied to Ubuntu 7.10 and 8.04 LTS. (CVE-2008-5184)
It was discovered that the PNG filter in CUPS did not properly handle certain
malformed images. If a user or automated system were tricked into opening a
crafted PNG image file, a remote attacker could
Debian
CVE-2008-5377: cups - pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a syml...
vendor_debian·2008·CVSS 1.2
CVE-2008-5377 [LOW] CVE-2008-5377: cups - pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a syml...
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny1)
bullseye: resolved (fixed in 1.3.8-1lenny1)
forky: resolved (fixed in 1.3.8-1lenny1)
sid: resolved (fixed in 1.3.8-1lenny1)
trixie: resolved (fixed in 1.3.8-1lenny1)
Red Hat
CVE-2008-5377: pstopdf in CUPS 1
vendor_redhat·CVSS 1.2
CVE-2008-5377 [LOW] CVE-2008-5377: pstopdf in CUPS 1
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Statement: Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Affected script is not part of the upstream CUPS distribution, but rather an addition used by Debian-based distributions (and possibly others).
CUPS packages as shipped in Red Hat Enterprise Linux 5 also provide pstopdf filter. However, that filter is different from the one used in Debian-based distributions, and is unaffected by this flaw.
Additionally, all filters used by CUPS on all versions of Red Hat Enterprise Linux are run under an unprivileged "lp" user, making the root privilege es
No detection rules found.
No writeups or analysis indexed.
2008-12-08
Published