Debian Cups vulnerabilities
116 known vulnerabilities affecting debian/cups.
Total CVEs
116
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH27MEDIUM49LOW27
Vulnerabilities
Page 2 of 6
CVE-2010-2941P3CRITICALCVSS 9.8fixed in cups 1.4.4-7 (bookworm)2010
CVE-2010-2941 [CRITICAL] CVE-2010-2941: cups - ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for a...
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
Scope: local
bookworm: resolved (fixed in 1.4.4-7)
bullseye: resolved (fixed in 1
debian
CVE-2009-2820P4LOWCVSS 4.3PoCfixed in cups 1.4.2-1 (bookworm)2009
CVE-2009-2820 [MEDIUM] CVE-2009-2820: cups - The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 ...
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print s
debian
CVE-2008-0882P3MEDIUMCVSS 10.0fixed in cups 1.3.6-1 (bookworm)2008
CVE-2008-0882 [CRITICAL] CVE-2008-0882: cups - Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allo...
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information
debian
CVE-2008-0047P3MEDIUMCVSS 9.3fixed in cups 1.3.6-3 (bookworm)2008
CVE-2008-0047 [CRITICAL] CVE-2008-0047: cups - Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and o...
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
Scope: local
bookworm: resolved (fixed in 1.3.6-3)
bullseye: resolved (fixed in 1.3.6-3)
forky: resolv
debian
CVE-2004-1269P4MEDIUMCVSS 5.0PoCfixed in cups 1.1.22-2 (bookworm)2004
CVE-2004-1269 [MEDIUM] CVE-2004-1269: cups - lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a f...
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fi
debian
CVE-2007-4351P3MEDIUMCVSS 10.0fixed in cups 1.3.4-1 (bookworm)2007
CVE-2007-4351 [CRITICAL] CVE-2007-4351: cups - Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows re...
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.4-1)
bullseye: resolved (fixed in 1.3.4-1)
forky: re
debian
CVE-2007-5392P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5392 [CRITICAL] CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1...
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: r
debian
CVE-2008-3639P3MEDIUMCVSS 7.5fixed in cups 1.3.8-1lenny2 (bookworm)2008
CVE-2008-3639 [HIGH] CVE-2008-3639: cups - Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS befor...
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny2)
bullseye: resolved (fixed in 1.3.8-1lenny2)
forky: resolved (fixed i
debian
CVE-2018-6553P3HIGHCVSS 8.8fixed in cups 2.2.8-5 (bookworm)2018
CVE-2018-6553 [HIGH] CVE-2018-6553: cups - The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of h...
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 L
debian
CVE-2003-0195P4MEDIUMCVSS 5.0PoCfixed in cups 1.1.19final-1 (bookworm)2003
CVE-2003-0195 [MEDIUM] CVE-2003-0195: cups - CUPS before 1.1.19 allows remote attackers to cause a denial of service via a pa...
CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.
Scope: local
bookworm: resolved (fixed in 1.1.19final-1)
bullseye: resolved (fixed in 1.1.19final-1)
forky: resolved (fixed in 1.1.19final-1)
sid: resolved (fixed in 1.1.19final-1)
trixie: resolved (fixed in 1.1.19final-
debian
CVE-2008-5377P4LOWCVSS 1.2PoCfixed in cups 1.3.8-1lenny1 (bookworm)2008
CVE-2008-5377 [LOW] CVE-2008-5377: cups - pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a syml...
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny1)
bullseye: resolved (fixed in 1.3.8-1lenny1)
forky: resolved (fixed in 1.3.8-1lenny1)
sid: resolved (fixed in 1.3.8-1lenny1)
trixie: resolved
debian
CVE-2015-3279P3HIGHCVSS 7.5fixed in cups 1.5.0-16 (bookworm)2015
CVE-2015-3279 [HIGH] CVE-2015-3279: cups - Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.7...
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.5.0-16)
bullseye: resolved (fixed in 1.5.0-16)
forky: resolved (fi
debian
CVE-2007-5393P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5393 [CRITICAL] CVE-2007-5393: cups - Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream...
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22
debian
CVE-2008-5286P3MEDIUMCVSS 7.5fixed in cups 1.3.8-1lenny4 (bookworm)2008
CVE-2008-5286 [HIGH] CVE-2008-5286: cups - Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 ...
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny4)
bullseye: resolved (fixed in 1.3.8-1lenny4)
forky: resolved (fixed in 1.3.8-1
debian
CVE-2007-4352P3HIGHCVSS 7.6fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-4352 [HIGH] CVE-2007-4352: cups - Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Strea...
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: re
debian
CVE-2002-1369P3CRITICALCVSS 10.0fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1369 [CRITICAL] CVE-2002-1369: cups - jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not prop...
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid:
debian
CVE-2007-3387P3LOWCVSS 6.8fixed in libextractor 0.5.12-1 (bookworm)2007
CVE-2007-3387 [MEDIUM] CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ...
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine fu
debian
CVE-2024-35235P3MEDIUMCVSS 4.4fixed in cups 2.4.2-3+deb12u6 (bookworm)2024
CVE-2024-35235 [MEDIUM] CVE-2024-35235: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given tha
debian
CVE-2020-3898P3HIGHCVSS 7.8fixed in cups 2.3.1-12 (bookworm)2020
CVE-2020-3898 [HIGH] CVE-2020-3898: cups - A memory corruption issue was addressed with improved validation. This issue is ...
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
Scope: local
bookworm: resolved (fixed in 2.3.1-12)
bullseye: resolved (fixed in 2.3.1-12)
forky: resolved (fixed in 2.3.1-12)
sid: resolved (fixed in 2.3.1-12)
trixie: resolved (fixed in 2.3.1-12)
debian
CVE-2011-2896P3HIGHCVSS 7.5fixed in cups 1.5.0-8 (bookworm)2011
CVE-2011-2896 [HIGH] CVE-2011-2896: cups - The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Kobl...
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other pro
debian