CVE-2009-0163
published 2009-04-23CVE-2009-0163: Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.25%
90.0th percentile
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.9 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5x2p-gch7-phhj: Integer overflow in the TIFF image decoding routines in CUPS 1
ghsa_unreviewed·2022-05-02
CVE-2009-0163 [MEDIUM] GHSA-5x2p-gch7-phhj: Integer overflow in the TIFF image decoding routines in CUPS 1
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
OSV
CVE-2009-0163: Integer overflow in the TIFF image decoding routines in CUPS 1
osv·2009-04-23·CVSS 6.8
CVE-2009-0163 [MEDIUM] CVE-2009-0163: Integer overflow in the TIFF image decoding routines in CUPS 1
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
Red Hat
cups: Integer overflow in the TIFF image filter
vendor_redhat·2009-04-16·CVSS 6.8
CVE-2009-0163 [MEDIUM] CWE-190 cups: Integer overflow in the TIFF image filter
cups: Integer overflow in the TIFF image filter
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2009-04-16
CVE-2009-0163 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS vulnerability
It was discovered that CUPS did not properly check the height of TIFF images.
If a user or automated system were tricked into opening a crafted TIFF image
file, a remote attacker could cause a denial of service or possibly execute
arbitrary code with user privileges. In Ubuntu 7.10, 8.04 LTS, and 8.10,
attackers would be isolated by the AppArmor CUPS profile.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-0163: cups - Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier a...
vendor_debian·2009·CVSS 6.8
CVE-2009-0163 [MEDIUM] CVE-2009-0163: cups - Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier a...
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.10-1)
bullseye: resolved (fixed in 1.3.10-1)
forky: resolved (fixed in 1.3.10-1)
sid: resolved (fixed in 1.3.10-1)
trixie: resolved (fixed in 1.3.10-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://secunia.com/advisories/34481http://secunia.com/advisories/34722http://secunia.com/advisories/34747http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.cups.org/articles.php?L582http://www.cups.org/str.php?L3031http://www.debian.org/security/2009/dsa-1773http://www.redhat.com/support/errata/RHSA-2009-0428.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/bid/34571http://www.securitytracker.com/id?1022070http://www.ubuntu.com/usn/usn-760-1https://bugzilla.redhat.com/show_bug.cgi?id=490596https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11546http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://secunia.com/advisories/34481http://secunia.com/advisories/34722http://secunia.com/advisories/34747http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.cups.org/articles.php?L582http://www.cups.org/str.php?L3031http://www.debian.org/security/2009/dsa-1773http://www.redhat.com/support/errata/RHSA-2009-0428.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/bid/34571http://www.securitytracker.com/id?1022070http://www.ubuntu.com/usn/usn-760-1https://bugzilla.redhat.com/show_bug.cgi?id=490596https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11546
2009-04-23
Published