[cupsys] [CVE-2007-5849] [CVE-2007-6358] local vulnerabilities

Bug #180296 reported by disabled.user
254
Affects Status Importance Assigned to Milestone
cupsys (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: cupsys

References:
DSA-1437-1 (http://www.debian.org/security/2007/dsa-1437)

Quoting:
"Several local vulnerabilities have been discovered in the Common UNIX
Printing System. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2007-5849

    Wei Wang discovered that an buffer overflow in the SNMP backend
    may lead to the execution of arbitrary code.

CVE-2007-6358

    Elias Pipping discovered that insecure handling of a temporary
    file in the pdftops.pl script may lead to local denial of service.
    This vulnerability is not exploitable in the default configuration."

CVE References

Revision history for this message
Jamie Strandboge (jdstrand) wrote :
Changed in cupsys:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.