Back

HIGH

cups boundary error

Published Oct 31, 2007

Description

Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.

Affected products

Remediation

Red Hat statement

Vulnerable. This issue affected the CUPS packages in Red Hat Enterprise Linux 5. This issue also affected the versions of CUPS packages in Red Hat Enterprise Linux 3 and 4, but exploitation would only lead to a possible denial of service.

Metrics

Weaknesses (1)

References (44)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Oct 31, 2007
Updated Aug 7, 2024
Reserved Aug 14, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 31, 2007