CVE-2014-4337Improper Restriction of Operations within the Bounds of a Memory Buffer in Cups-filters

Severity
4.3MEDIUMNVD
EPSS
2.1%
top 15.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 14

Description

The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-chh5-m35x-x292: The process_browse_data function in utils/cups-browsed2022-05-14
OSV
CVE-2014-4337: The process_browse_data function in utils/cups-browsed2014-06-22
CVEList
CVE-2014-4337: The process_browse_data function in utils/cups-browsed2014-06-22

📋Vendor Advisories

2
Red Hat
cups-filters: cups-browsed DoS via process_browse_data() OOB read2014-04-23
Debian
CVE-2014-4337: cups-filters - The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups...2014

💬Community

1
Bugzilla
CVE-2014-4337 cups-filters: cups-browsed DoS via process_browse_data() OOB read2014-06-20
CVE-2014-4337 — Cups-filters vulnerability | cvebase