Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Cups | — | Apply OS X security update 2007-009 | Dec 16, 2011 | Oct 31, 2007 |
| Debian | — | Upgrade cups | Jul 30, 2024 | Oct 31, 2007 |
| Freebsd | — | Upgrade cups-base | Dec 10, 2025 | Nov 9, 2007 |
| Gentoo Linux | — | Upgrade net-print/cups. | Oct 30, 2017 | Oct 31, 2007 |
| Oracle_linux | — | Upgrade cups-libsUpgrade cupsUpgrade cups-develUpgrade cups-lpd | Oct 16, 2024 | Oct 31, 2007 |
| Suse | — | Upgrade cups-ddkUpgrade cups-clientUpgrade libcupsimage2Upgrade cups-libsUpgrade cups-libs-x86Upgrade cups-libs-32bitUpgrade libcups2Upgrade cups-configUpgrade cupsUpgrade cups-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade cupsys | Nov 8, 2024 | Oct 31, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub