Summary
The remote host is missing an update to cupsys
announced via advisory DSA 1625-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201625-1
Insight
Several remote vulnerabilities have been discovered in the Common Unix Printing System (CUPS). The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-0053
Buffer overflows in the HP-GL input filter allowed to possibly run arbitrary code through crafted HP-GL files.
CVE-2008-1373
Buffer overflow in the GIF filter allowed to possibly run arbitrary code through crafted GIF files.
CVE-2008-1722
Integer overflows in the PNG filter allowed to possibly run arbitrary code through crafted PNG files.
For the stable distribution (etch), these problems have been fixed in version 1.2.7-4etch4 of package cupsys.
For the testing (lenny) and unstable distribution (sid), these problems have been fixed in version 1.3.7-2 of package cups.
We recommend that you upgrade your cupsys package.
Severity
Classification
-
CVE CVE-2008-0053, CVE-2008-1373, CVE-2008-1722 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities