FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-3640

This CVE name corresponds to:

Entered Topic
2008-10-10 cups -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-3640
Phase Assigned(20080812)

Description

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.

References

Source Reference
IDEFENSE 20081009 Multiple Vendor CUPS texttops Integer Overflow Vulnerability
CONFIRM http://www.cups.org/articles.php?L575
CONFIRM http://www.cups.org/str.php?L2919
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2008-470.htm
DEBIAN DSA-1656
FEDORA FEDORA-2008-8801
FEDORA FEDORA-2008-8844
GENTOO GLSA-200812-11
MANDRIVA MDVSA-2008:211
REDHAT RHSA-2008:0937
SUNALERT 261088
SUSE SUSE-SR:2008:021
UBUNTU USN-656-1
BID 31690
OVAL oval:org.mitre.oval:def:10266
SECUNIA 33085
SECUNIA 33111
SECUNIA 32331
VUPEN ADV-2008-2782
VUPEN ADV-2008-3401
SECTRACK 1021034
SECUNIA 32084
SECUNIA 32226
SECUNIA 32316
SECUNIA 32284
SECUNIA 32292
VUPEN ADV-2009-1568
XF cups-writeprolog-bo(45790)