CVE-2008-0047
Published: 18 March 2008
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
Notes
Author | Note |
---|---|
jdstrand | CUPS 1.2.0 through 1.3.6 cgiCompileSearch() heap overflow |
Priority
Status
Package | Release | Status |
---|---|---|
cupsys Launchpad, Ubuntu, Debian |
dapper |
Released
(1.2.2-0ubuntu0.6.06.8)
|
edgy |
Released
(1.2.4-2ubuntu3.3)
|
|
feisty |
Released
(1.2.8-0ubuntu8.3)
|
|
gutsy |
Released
(1.3.2-1ubuntu7.6)
|
|
upstream |
Released
(1.3.7)
|
|
Patches: vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=472105 |