Debian Cups vulnerabilities
116 known vulnerabilities affecting debian/cups.
Total CVEs
116
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH27MEDIUM49LOW27
Vulnerabilities
Page 3 of 6
CVE-2002-1383P3CRITICALCVSS 10.0fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1383 [CRITICAL] CVE-2002-1383: cups - Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through ...
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
debian
CVE-2005-3192P3LOWCVSS 7.5fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2002-1367P3CRITICALCVSS 10.0fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1367 [CRITICAL] CVE-2002-1367: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers...
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
Scope: local
bookworm: resolv
debian
CVE-2004-0888P4CRITICALCVSS 10.0fixed in cups 1.1.22-6 (bookworm)2004
CVE-2004-0888 [CRITICAL] CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fi
debian
CVE-2008-3640P3MEDIUMCVSS 6.8fixed in cups 1.3.8-1lenny2 (bookworm)2008
CVE-2008-3640 [MEDIUM] CVE-2008-3640: cups - Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 al...
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.8-1lenny2)
bullseye: resolved (fixed in 1.3.8-1lenny2)
forky: resolved (fixed in 1.3.8-1lenny2)
sid: resolved (fixed in 1.3
debian
CVE-2009-0163P3MEDIUMCVSS 6.8fixed in cups 1.3.10-1 (bookworm)2009
CVE-2009-0163 [MEDIUM] CVE-2009-0163: cups - Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier a...
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow
debian
CVE-2018-4180P3HIGHCVSS 7.8fixed in cups 2.2.8-2 (bookworm)2018
CVE-2018-4180 [HIGH] CVE-2018-4180: cups - In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was ad...
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
Scope: local
bookworm: resolved (fixed in 2.2.8-2)
bullseye: resolved (fixed in 2.2.8-2)
forky: resolved (fixed in 2.2.8-2)
sid: resolved (fixed in 2.2.8-2)
trixie: resolved (fixed in 2.2.8-2)
debian
CVE-2017-15400P3HIGHCVSS 7.8fixed in cups 2.2.3-2 (bookworm)2017
CVE-2017-15400 [HIGH] CVE-2017-15400: cups - Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62....
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
Scope: local
bookworm: resolved (fixed in 2.2.3-2)
bullseye: resolved (fixed in 2.2.3-2)
forky: resolved (fixed in 2.2.3-2)
sid:
debian
CVE-2013-6475P3MEDIUMCVSS 6.8fixed in cups 1.5.0-16 (bookworm)2013
CVE-2013-6475 [MEDIUM] CVE-2013-6475: cups - Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx ...
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.5.0-16)
bullseye: resolved (fixed in 1.5.0-16)
forky: resolved (fi
debian
CVE-2013-6474P3MEDIUMCVSS 6.8fixed in cups 1.5.0-16 (bookworm)2013
CVE-2013-6474 [MEDIUM] CVE-2013-6474: cups - Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters befo...
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 1.5.0-16)
bullseye: resolved (fixed in 1.5.0-16)
forky: resolved (fixed in 1.5.0-16)
sid: resolved (fixed in 1.5.0-16)
trixie: resolved (fixed in 1.5.0-16)
debian
CVE-2005-0064P3HIGHCVSS 7.5fixed in cups 1.1.22-6 (bookworm)2005
CVE-2005-0064 [HIGH] CVE-2005-0064: cups - Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.0...
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fixed in 1.1.22-6)
forky: resolved (fixed in 1.1.22-6)
sid: resolved (fixed in 1.1.22-6)
trixie
debian
CVE-2005-3627P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3627 [HIGH] CVE-2005-3627: cups - Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, t...
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index
debian
CVE-2004-1125P4CRITICALCVSS 9.3fixed in cups 1.1.22-2 (bookworm)2004
CVE-2004-1125 [CRITICAL] CVE-2004-1125: cups - Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other ...
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded
debian
CVE-2011-3170P3MEDIUMCVSS 5.1fixed in cups 1.5.0-8 (bookworm)2011
CVE-2011-3170 [MEDIUM] CVE-2011-3170: cups - The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does n...
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Scope: local
bookworm: resolved (fixed in 1.5.0-8)
bullsey
debian
CVE-2014-9679P4MEDIUMCVSS 6.8fixed in cups 1.7.5-11 (bookworm)2014
CVE-2014-9679 [MEDIUM] CVE-2014-9679: cups - Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUP...
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.7.5-11)
bullseye: resolved (fixed in 1.7.5-11)
forky: resolved (fixed in 1.7.5-11)
sid: resolved (fixed in
debian
CVE-2025-61915P4MEDIUMCVSS 6.0fixed in cups 2.4.15-1 (forky)2025
CVE-2025-61915 [MEDIUM] CVE-2025-61915: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2
debian
CVE-2010-0542P4MEDIUMCVSS 6.8fixed in cups 1.4.4-1 (bookworm)2010
CVE-2010-0542 [MEDIUM] CVE-2010-0542: cups - The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem...
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.
debian
CVE-2023-34241P4MEDIUMCVSS 5.3fixed in cups 2.4.2-3+deb12u1 (bookworm)2023
CVE-2023-34241 [MEDIUM] CVE-2023-34241: cups - OpenPrinting CUPS is a standards-based, open source printing system for Linux an...
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts the entire cups
debian
CVE-2002-1371P4HIGHCVSS 7.5fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1371 [HIGH] CVE-2002-1371: cups - filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 ...
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid:
debian
CVE-2005-3628P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3628 [HIGH] CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
f
debian