cups: buffer overflows in HP-GL/2 filter
Published Mar 18, 2008
10.0
HIGHCVSS 2.0
EPSS 8.28%
Description
Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.
Affected products
No data.
- ≤ 1.3.5
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.5-1
- 1.1.5-2
- 1.1.6
- 1.1.6-1
- 1.1.6-2
- 1.1.6-3
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.9-1
- 1.1.10
- 1.1.10-1
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 1.1.18
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.21
- 1.1.21
- 1.1.21
- 1.1.22
- 1.1.22
- 1.1.22
- 1.1.23
- 1.1.23
- 1.2
- 1.2
- 1.2
- 1.2
- 1.2
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.2.10
- 1.2.11
- 1.2.12
- 1.3
- 1.3
- 1.3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.9
- 1.4.1
No data.
Red Hat Enterprise Linux 3
cups-1:1.1.17-13.3.52
Fixed · RHSA-2008:0206
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.20.2.el4_6.6
Fixed · RHSA-2008:0206
Red Hat Enterprise Linux 5
cups-1:1.2.4-11.14.el5_1.6
Fixed · RHSA-2008:0192
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | cups-1:1.1.17-13.3.52 | Fixed | RHSA-2008:0206 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.20.2.el4_6.6 | Fixed | RHSA-2008:0206 |
| Red Hat Enterprise Linux 5 | cups-1:1.2.4-11.14.el5_1.6 | Fixed | RHSA-2008:0192 |
No package ranges for this CVE.
Remediation
Red Hat statement
NVD clarification: To exploit this flaw an attacker needs to print a malicious file through the vulnerable filter (either themselves or by convincing a victim to do so), it should therefore be AC:M In CUPS, print filters run as an unprivileged user no superuser (root), therefore this should be scored C:P, I:P, A:P
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.28% (0.08282) | 94.75th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.28% (0.08282) | 94.19th | v5 (v2026.06.15) |
| Sep 8, 2025 | 27.57% (0.27566) | 96.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 17.19% (0.17193) | 94.47th | v4 (v2025.03.14) |
| Mar 29, 2025 | 29.33% (0.29332) | 94.62th | v4 (v2025.03.14) |
| Mar 17, 2025 | 17.59% (0.17585) | 94.58th | v4 (v2025.03.14) |
| Feb 27, 2025 | 74.16% (0.74161) | 98.39th | v3 (v2023.03.01) |
| Dec 17, 2024 | 70.19% (0.70191) | 98.21th | v3 (v2023.03.01) |
| Dec 13, 2024 | 16.52% (0.16523) | 96.20th | v3 (v2023.03.01) |
| Aug 20, 2024 | 21.37% (0.21372) | 96.52th | v3 (v2023.03.01) |
| Jun 7, 2024 | 11.67% (0.11674) | 95.29th | v3 (v2023.03.01) |
| Jan 13, 2024 | 11.71% (0.11713) | 94.77th | v3 (v2023.03.01) |
| Jun 12, 2023 | 11.74% (0.11737) | 94.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 10.77% (0.10770) | 94.12th | v3 (v2023.03.01) |
| Mar 6, 2023 | 11.35% (0.11354) | 95.03th | v2 (v2022.01.01) |
| Apr 1, 2022 | 11.35% (0.11354) | 94.63th | v2 (v2022.01.01) |
| Feb 4, 2022 | 11.35% (0.11354) | 88.73th | v2 (v2022.01.01) |
References (30)
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLEPatch
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00003.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29573 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29603 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29630 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29634 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29655 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29659 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29750 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31324 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200804-01.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2008/dsa-1625 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:081 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0192.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0206.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/28304 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/28334 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1019672 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-598-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA08-079A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2008-0053 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=438117 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41272 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-0053
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10356 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-0053
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.