CVE-2009-0577
published 2009-02-20CVE-2009-0577: Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.58%
88.2th percentile
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjcq-j2gf-3gvx: Integer overflow in the WriteProlog function in texttops in CUPS 1
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-0577 [MEDIUM] GHSA-cjcq-j2gf-3gvx: Integer overflow in the WriteProlog function in texttops in CUPS 1
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
Red Hat
cups-CVE-2008-3640.patch has been corrupted.
vendor_redhat·2009-02-17·CVSS 6.8
CVE-2009-0577 [MEDIUM] cups-CVE-2008-3640.patch has been corrupted.
cups-CVE-2008-3640.patch has been corrupted.
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/33995http://support.avaya.com/elmodocs2/security/ASA-2009-064.htmhttp://www.redhat.com/support/errata/RHSA-2009-0308.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=486052https://exchange.xforce.ibmcloud.com/vulnerabilities/48977https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9968http://secunia.com/advisories/33995http://support.avaya.com/elmodocs2/security/ASA-2009-064.htmhttp://www.redhat.com/support/errata/RHSA-2009-0308.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=486052https://exchange.xforce.ibmcloud.com/vulnerabilities/48977https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9968
2009-02-20
Published