CVE Vulnerabilities

CVE-2008-5286

Published: Dec 01, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
CupsApple1.1.17 (including)1.1.17 (including)
CupsApple1.1.18 (including)1.1.18 (including)
CupsApple1.1.19 (including)1.1.19 (including)
CupsApple1.1.19-rc1 (including)1.1.19-rc1 (including)
CupsApple1.1.19-rc2 (including)1.1.19-rc2 (including)
CupsApple1.1.19-rc3 (including)1.1.19-rc3 (including)
CupsApple1.1.19-rc4 (including)1.1.19-rc4 (including)
CupsApple1.1.19-rc5 (including)1.1.19-rc5 (including)
CupsApple1.1.20 (including)1.1.20 (including)
CupsApple1.1.20-rc1 (including)1.1.20-rc1 (including)
CupsApple1.1.20-rc2 (including)1.1.20-rc2 (including)
CupsApple1.1.20-rc3 (including)1.1.20-rc3 (including)
CupsApple1.1.20-rc4 (including)1.1.20-rc4 (including)
CupsApple1.1.20-rc5 (including)1.1.20-rc5 (including)
CupsApple1.1.20-rc6 (including)1.1.20-rc6 (including)
CupsApple1.1.21 (including)1.1.21 (including)
CupsApple1.1.21-rc1 (including)1.1.21-rc1 (including)
CupsApple1.1.21-rc2 (including)1.1.21-rc2 (including)
CupsApple1.1.22 (including)1.1.22 (including)
CupsApple1.1.22-rc1 (including)1.1.22-rc1 (including)
CupsApple1.1.22-rc2 (including)1.1.22-rc2 (including)
CupsApple1.1.23 (including)1.1.23 (including)
CupsApple1.1.23-rc1 (including)1.1.23-rc1 (including)
CupsApple1.2-b1 (including)1.2-b1 (including)
CupsApple1.2-b2 (including)1.2-b2 (including)
CupsApple1.2-rc1 (including)1.2-rc1 (including)
CupsApple1.2-rc2 (including)1.2-rc2 (including)
CupsApple1.2-rc3 (including)1.2-rc3 (including)
CupsApple1.2.0 (including)1.2.0 (including)
CupsApple1.2.1 (including)1.2.1 (including)
CupsApple1.2.2 (including)1.2.2 (including)
CupsApple1.2.3 (including)1.2.3 (including)
CupsApple1.2.4 (including)1.2.4 (including)
CupsApple1.2.5 (including)1.2.5 (including)
CupsApple1.2.6 (including)1.2.6 (including)
CupsApple1.2.7 (including)1.2.7 (including)
CupsApple1.2.8 (including)1.2.8 (including)
CupsApple1.2.9 (including)1.2.9 (including)
CupsApple1.2.10 (including)1.2.10 (including)
CupsApple1.2.11 (including)1.2.11 (including)
CupsApple1.2.12 (including)1.2.12 (including)
CupsApple1.3-b1 (including)1.3-b1 (including)
CupsApple1.3-rc1 (including)1.3-rc1 (including)
CupsApple1.3-rc2 (including)1.3-rc2 (including)
CupsApple1.3.0 (including)1.3.0 (including)
CupsApple1.3.1 (including)1.3.1 (including)
CupsApple1.3.2 (including)1.3.2 (including)
CupsApple1.3.3 (including)1.3.3 (including)
CupsApple1.3.4 (including)1.3.4 (including)
CupsApple1.3.5 (including)1.3.5 (including)
CupsApple1.3.6 (including)1.3.6 (including)
CupsApple1.3.7 (including)1.3.7 (including)
CupsApple1.3.8 (including)1.3.8 (including)
CupsApple1.3.9 (including)1.3.9 (including)
Red Hat Enterprise Linux 3RedHatcups-1:1.1.17-13.3.55*
CupsUbuntuintrepid*
CupsysUbuntudapper*
CupsysUbuntugutsy*
CupsysUbuntuhardy*

References