FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-3639

This CVE name corresponds to:

Entered Topic
2008-10-10 cups -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-3639
Phase Assigned(20080812)

Description

Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.

References

Source Reference
IDEFENSE 20081009 Multiple Vendor CUPS SGI imagetops Heap Overflow Vulnerability
CONFIRM http://www.cups.org/articles.php?L575
CONFIRM http://www.cups.org/str.php?L2918
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2008-470.htm
DEBIAN DSA-1656
FEDORA FEDORA-2008-8801
FEDORA FEDORA-2008-8844
GENTOO GLSA-200812-11
MANDRIVA MDVSA-2008:211
REDHAT RHSA-2008:0937
SUNALERT 261088
SUSE SUSE-SR:2008:021
UBUNTU USN-656-1
BID 31690
OVAL oval:org.mitre.oval:def:11464
SECUNIA 33085
SECUNIA 33111
SECUNIA 32331
VUPEN ADV-2008-2782
VUPEN ADV-2008-3401
SECTRACK 1021033
SECUNIA 32084
SECUNIA 32226
SECUNIA 32316
SECUNIA 32284
SECUNIA 32292
VUPEN ADV-2009-1568
XF cups-readrle16-bo(45789)