CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
BID:36350
Info
CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 36350 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2807 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 10 2009 12:00AM |
| Updated: | Sep 14 2009 07:41PM |
| Credit: | Reported in Apple Security Update 2009-005 |
| Vulnerable: |
Easy Software Products CUPS 1.3.10 Easy Software Products CUPS 1.3.9 Easy Software Products CUPS 1.3.8 Easy Software Products CUPS 1.3.7 Easy Software Products CUPS 1.3.6 Easy Software Products CUPS 1.3.5 Easy Software Products CUPS 1.3.3 Easy Software Products CUPS 1.3.2 Easy Software Products CUPS 1.2.12 Easy Software Products CUPS 1.2.10 Easy Software Products CUPS 1.2.9 Easy Software Products CUPS 1.2.8 Easy Software Products CUPS 1.2.4 Easy Software Products CUPS 1.2.2 Easy Software Products CUPS 1.1.23 rc1 Easy Software Products CUPS 1.1.23 Easy Software Products CUPS 1.1.22 rc1 Easy Software Products CUPS 1.1.22 Easy Software Products CUPS 1.1.21 Easy Software Products CUPS 1.1.20 Easy Software Products CUPS 1.1.19 rc5 Easy Software Products CUPS 1.1.19 Easy Software Products CUPS 1.1.18 Easy Software Products CUPS 1.1.17 Easy Software Products CUPS 1.1.16 Easy Software Products CUPS 1.1.15 Easy Software Products CUPS 1.1.14 Easy Software Products CUPS 1.1.13 Easy Software Products CUPS 1.1.12 Easy Software Products CUPS 1.1.10 Easy Software Products CUPS 1.1.7 Easy Software Products CUPS 1.1.6 Easy Software Products CUPS 1.1.4 -5 Easy Software Products CUPS 1.1.4 -3 Easy Software Products CUPS 1.1.4 -2 Easy Software Products CUPS 1.1.4 Easy Software Products CUPS 1.1.1 Easy Software Products CUPS 1.0.4 -8 Easy Software Products CUPS 1.0.4 DrPhibez and Nitro187 Guild FTPD 1.1.19 rc5 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
| Not Vulnerable: | |
Discussion
CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
CUPS (Common UNIX Printing System) is prone to a local heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Exploiting this issue will allow local attackers to execute arbitrary code with superuser privileges and completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
CUPS (Common UNIX Printing System) is prone to a local heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Exploiting this issue will allow local attackers to execute arbitrary code with superuser privileges and completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X Server 10.5.8
Apple Mac OS X 10.5.8
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X Server 10.5.8
-
Apple SecUpdSrvr2009-005.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.5.8
-
Apple SecUpd2009-005.dmg
http://www.apple.com/support/downloads/
References
CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
References:
References:
- CUPS Product Page (Easy Software Products)