Xpdf/CUPS pdftops Integer Overflow Vulnerability
BID:6475
Info
Xpdf/CUPS pdftops Integer Overflow Vulnerability
| Bugtraq ID: | 6475 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1384 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2002 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | Discovery of this issue is credited to zen-parse. |
| Vulnerable: |
Xpdf Xpdf 2.0 1 Xpdf Xpdf 2.0 Xpdf Xpdf 1.0 1 Xpdf Xpdf 1.0 0a Xpdf Xpdf 1.0 0 Xpdf Xpdf 0.93 Xpdf Xpdf 0.92 Xpdf Xpdf 0.91 Xpdf Xpdf 0.90 Easy Software Products CUPS 1.1.17 Easy Software Products CUPS 1.1.14 Easy Software Products CUPS 1.1.13 Easy Software Products CUPS 1.1.10 Easy Software Products CUPS 1.1.7 Easy Software Products CUPS 1.1.6 Easy Software Products CUPS 1.1.4 -5 Easy Software Products CUPS 1.1.4 -3 Easy Software Products CUPS 1.1.4 -2 Easy Software Products CUPS 1.1.4 Easy Software Products CUPS 1.1.1 Easy Software Products CUPS 1.0.4 -8 Easy Software Products CUPS 1.0.4 |
| Not Vulnerable: |
Easy Software Products CUPS 1.1.18 |
Discussion
Xpdf/CUPS pdftops Integer Overflow Vulnerability
The Xpdf/CUPS pdftops filter is prone to an integer overflow. As a result, it may be possible to corrupt memory with attacker-supplied data and cause arbitrary code to be executed.
The method of exploitation may vary. If an attacker can entice a user to print a malformed file from the command line using the vulnerable filter, it may be possible to execute code with the privileges of that user. Other methods of exploitation may allow the attacker to gain elevated privileges (such as that of the 'lp' user).
The Xpdf/CUPS pdftops filter is prone to an integer overflow. As a result, it may be possible to corrupt memory with attacker-supplied data and cause arbitrary code to be executed.
The method of exploitation may vary. If an attacker can entice a user to print a malformed file from the command line using the vulnerable filter, it may be possible to execute code with the privileges of that user. Other methods of exploitation may allow the attacker to gain elevated privileges (such as that of the 'lp' user).
Exploit / POC
Xpdf/CUPS pdftops Integer Overflow Vulnerability
iDefense has developed a functional exploit, however it has not been released to the public.
iDefense has developed a functional exploit, however it has not been released to the public.
References
Xpdf/CUPS pdftops Integer Overflow Vulnerability
References:
References:
- iDEFENSE Security Advisory 12.23.02: Integer Overflow in pdftops ("iDEFENSE Labs"
)