Back

HIGH

CUPS SNMP backend buffer overflow

Published Dec 19, 2007

Description

Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

Affected products

Remediation

Red Hat statement

Not vulnerable. This flaw does not affect the version of CUPS shipped in Red Hat Enterprise Linux 3 or 4. After a detailed analysis of this flaw, it has been determined it does not pose a security threat on Red Hat Enterprise Linux 5. For more details regarding this analysis, please see: https://bugzilla.redhat.com/show_bug.cgi?id=415131

Metrics

Weaknesses (1)

References (30)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 19, 2007
Updated Aug 7, 2024
Reserved Nov 6, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Dec 13, 2007