Debian Cups vulnerabilities

133 known vulnerabilities affecting debian/cups.

Total CVEs
133
CISA KEV
0
Public exploits
16
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH27MEDIUM56LOW37

Vulnerabilities

Page 3 of 7
CVE-2014-5031MEDIUMCVSS 5.0fixed in cups 1.7.4-2 (bookworm)2014
CVE-2014-5031 [MEDIUM] CVE-2014-5031: cups - The web interface in CUPS before 2.0 does not check that files have world-readab... The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.7.4-2) bullseye: resolved (fixed in 1.7.4-2) forky: resolved (fixed in 1.7.4-2) sid: resolved (fixed in 1.7.4-2) trixie: resolved (fixed in 1.7
debian
CVE-2014-9679MEDIUMCVSS 6.8fixed in cups 1.7.5-11 (bookworm)2014
CVE-2014-9679 [MEDIUM] CVE-2014-9679: cups - Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUP... Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 1.7.5-11) bullseye: resolved (fixed in 1.7.5-11) forky: resolved (fixed in 1.7.5-11) sid: resolved (fixed in
debian
CVE-2014-2856MEDIUMCVSS 4.3fixed in cups 1.7.2-1 (bookworm)2014
CVE-2014-2856 [MEDIUM] CVE-2014-2856: cups - Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Pr... Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function. Scope: local bookworm: resolved (fixed in 1.7.2-1) bullseye: resolved (fixed in 1.7.2-1) forky: resolved (fixed in 1.7.2-1) sid: resol
debian
CVE-2014-5030LOWCVSS 1.9fixed in cups 1.7.4-2 (bookworm)2014
CVE-2014-5030 [LOW] CVE-2014-5030: cups - CUPS before 2.0 allows local users to read arbitrary files via a symlink attack ... CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py. Scope: local bookworm: resolved (fixed in 1.7.4-2) bullseye: resolved (fixed in 1.7.4-2) forky: resolved (fixed in 1.7.4-2) sid: resolved (fixed in 1.7.4-2) trixie: resolved (fixed in 1.7.4-2)
debian
CVE-2014-8166LOWCVSS 8.82014
CVE-2014-8166 [HIGH] CVE-2014-8166: cups - The browsing feature in the server in CUPS does not filter ANSI escape sequences... The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2014-5029LOWCVSS 1.2fixed in cups 1.7.4-2 (bookworm)2014
CVE-2014-5029 [LOW] CVE-2014-5029: cups - The web interface in CUPS 1.7.4 allows local users in the lp group to read arbit... The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537. Scope: local bookworm: resolved (fixed in 1.7.4-2) bullseye: resolved (fixed in 1.7.4-2) forky: resolved (fixed in 1.7.
debian
CVE-2014-3537LOWCVSS 1.2fixed in cups 1.7.4-1 (bookworm)2014
CVE-2014-3537 [LOW] CVE-2014-3537: cups - The web interface in CUPS before 1.7.4 allows local users in the lp group to rea... The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/. Scope: local bookworm: resolved (fixed in 1.7.4-1) bullseye: resolved (fixed in 1.7.4-1) forky: resolved (fixed in 1.7.4-1) sid: resolved (fixed in 1.7.4-1) trixie: resolved (fixed in 1.7.4-1)
debian
CVE-2013-6475MEDIUMCVSS 6.8fixed in cups 1.5.0-16 (bookworm)2013
CVE-2013-6475 [MEDIUM] CVE-2013-6475: cups - Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx ... Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.5.0-16) bullseye: resolved (fixed in 1.5.0-16) forky: resolved (fi
debian
CVE-2013-6474MEDIUMCVSS 6.8fixed in cups 1.5.0-16 (bookworm)2013
CVE-2013-6474 [MEDIUM] CVE-2013-6474: cups - Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters befo... Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 1.5.0-16) bullseye: resolved (fixed in 1.5.0-16) forky: resolved (fixed in 1.5.0-16) sid: resolved (fixed in 1.5.0-16) trixie: resolved (fixed in 1.5.0-16)
debian
CVE-2013-6476MEDIUMCVSS 4.4fixed in cups 1.5.0-16 (bookworm)2013
CVE-2013-6476 [MEDIUM] CVE-2013-6476: cups - The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp fi... The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file. Scope: local bookworm: resolved (fixed in 1.5.0-16) bullseye: resolved (fixed in 1.5.0-16) forky: resolved (fixed in 1.5.0-16) sid: resolved (fi
debian
CVE-2013-6891LOWCVSS 1.2fixed in cups 1.7.1-1 (bookworm)2013
CVE-2013-6891 [LOW] CVE-2013-6891: cups - lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local... lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf. Scope: local bookworm: resolved (fixed in 1.7.1-1) bullseye: resolved (fixed in 1.7.1-1) forky: resolved (fixed in 1.7.1-1) sid: resolved (fixed in 1.7.1-1) tri
debian
CVE-2012-5519HIGHCVSS 7.2PoCfixed in cups 1.5.3-2.7 (bookworm)2012
CVE-2012-5519 [HIGH] CVE-2012-5519: cups - CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux... CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface. Scope: local bookworm: resolved (fixed in 1.5.3-2.7) bullseye: resolved (fix
debian
CVE-2012-6094LOWCVSS 9.82012
CVE-2012-6094 [CRITICAL] CVE-2012-6094: cups - cups (Common Unix Printing System) 'Listen localhost:631' option not honored cor... cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2011-2896HIGHCVSS 7.5fixed in cups 1.5.0-8 (bookworm)2011
CVE-2011-2896 [HIGH] CVE-2011-2896: cups - The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Kobl... The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other pro
debian
CVE-2011-3170MEDIUMCVSS 5.1fixed in cups 1.5.0-8 (bookworm)2011
CVE-2011-3170 [MEDIUM] CVE-2011-3170: cups - The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does n... The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896. Scope: local bookworm: resolved (fixed in 1.5.0-8) bullsey
debian
CVE-2010-2941CRITICALCVSS 9.8fixed in cups 1.4.4-7 (bookworm)2010
CVE-2010-2941 [CRITICAL] CVE-2010-2941: cups - ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for a... ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request. Scope: local bookworm: resolved (fixed in 1.4.4-7) bullseye: resolved (fixed in 1
debian
CVE-2010-0302HIGHCVSS 7.5fixed in cups 1.4.2-10 (bookworm)2010
CVE-2010-0302 [HIGH] CVE-2010-0302: cups - Use-after-free vulnerability in the abstract file-descriptor handling interface ... Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to i
debian
CVE-2010-0542MEDIUMCVSS 6.8fixed in cups 1.4.4-1 (bookworm)2010
CVE-2010-0542 [MEDIUM] CVE-2010-0542: cups - The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem... The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file. Scope: local bookworm: resolved (fixed in 1.
debian
CVE-2010-0393MEDIUMCVSS 6.9fixed in cups 1.4.2-9.1 (bookworm)2010
CVE-2010-0393 [MEDIUM] CVE-2010-0393: cups - The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.... The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers. Scope: local bookworm: resolved (fixed in 1.4.2
debian
CVE-2010-2432MEDIUMCVSS 5.0fixed in cups 1.4.4-1 (bookworm)2010
CVE-2010-2432 [MEDIUM] CVE-2010-2432: cups - The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, ... The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses. Scope: local bookworm: resolved (fixed in 1.4.4-1) bullseye: resolved (fixed in 1.4.4-1) forky: re
debian