CVE-2007-5849

Publication date 19 December 2007

Last updated 24 July 2024


Ubuntu priority

Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

Status

Package Ubuntu Release Status
cupsys 7.10 gutsy
Fixed 1.3.2-1ubuntu7.3
7.04 feisty
Fixed 1.2.8-0ubuntu8.2
6.10 edgy
Fixed 1.2.4-2ubuntu3.2
6.06 LTS dapper
Fixed 1.2.2-0ubuntu0.6.06.6

References

Related Ubuntu Security Notices (USN)

    • USN-563-1
    • CUPS vulnerabilities
    • 9 January 2008

Other references