Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cupsUpgrade cups-develUpgrade cups-libs | Dec 1, 2016 | Oct 14, 2008 |
| Debian | — | Upgrade cups | Jul 30, 2024 | Oct 14, 2008 |
| Freebsd | — | Upgrade cups-base | Dec 10, 2025 | Oct 10, 2008 |
| Gentoo Linux | — | Upgrade net-print/cups. | Oct 30, 2017 | Oct 14, 2008 |
| Oracle_linux | — | Upgrade cups-develUpgrade cupsUpgrade cups-lpdUpgrade cups-libs | Oct 16, 2024 | Oct 14, 2008 |
| Suse | — | Upgrade cups-develUpgrade cups-libs-32bitUpgrade cupsUpgrade cups-libs-x86Upgrade cups-libs-64bitUpgrade cups-clientUpgrade suse-releaseUpgrade cups-libs | Feb 17, 2015 | Oct 14, 2008 |
| Ubuntu | — | Upgrade cupsys | Nov 8, 2024 | Oct 14, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub