[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3641Date: (C)2008-10-10   (M)2024-01-04


The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1021031
http://www.securityfocus.com/archive/1/497221/100/0/threaded
SUNALERT-261088
BID-31681
BID-31688
SECUNIA-32084
SECUNIA-32222
SECUNIA-32226
SECUNIA-32284
SECUNIA-32292
SECUNIA-32316
SECUNIA-32331
SECUNIA-33085
SECUNIA-33111
SECUNIA-33568
ADV-2008-2780
ADV-2008-2782
ADV-2008-3401
ADV-2009-1568
APPLE-SA-2008-10-09
DSA-1656
FEDORA-2008-8801
FEDORA-2008-8844
GLSA-200812-11
MDVSA-2008:211
RHSA-2008:0937
SUSE-SR:2008:021
SUSE-SR:2009:002
USN-656-1
cups-hpgl-code-execution(45779)
http://support.apple.com/kb/HT3216
http://support.avaya.com/elmodocs2/security/ASA-2008-470.htm
http://www.cups.org/articles.php?L575
http://www.cups.org/str.php?L2911
http://www.zerodayinitiative.com/advisories/ZDI-08-067
oval:org.mitre.oval:def:9666

CPE    76
cpe:/a:apple:cups:1.2.12
cpe:/a:apple:cups:1.2.11
cpe:/a:apple:cups:1.3:rc1
cpe:/a:apple:cups:1.3:rc2
...
CWE    1
CWE-399
OVAL    3
oval:org.secpod.oval:def:301543
oval:org.mitre.oval:def:8170
oval:org.secpod.oval:def:102076

© SecPod Technologies