CVE-2008-3640

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
applecups
𝑥
≤ 1.3.8
applecups
1.1
applecups
1.1.1
applecups
1.1.2
applecups
1.1.3
applecups
1.1.4
applecups
1.1.5
applecups
1.1.5-1
applecups
1.1.5-2
applecups
1.1.6
applecups
1.1.6-1
applecups
1.1.6-2
applecups
1.1.6-3
applecups
1.1.7
applecups
1.1.8
applecups
1.1.9
applecups
1.1.9-1
applecups
1.1.10
applecups
1.1.10-1
applecups
1.1.11
applecups
1.1.12
applecups
1.1.13
applecups
1.1.14
applecups
1.1.15
applecups
1.1.16
applecups
1.1.17
applecups
1.1.18
applecups
1.1.19
applecups
1.1.19:rc1
applecups
1.1.19:rc2
applecups
1.1.19:rc3
applecups
1.1.19:rc4
applecups
1.1.19:rc5
applecups
1.1.20
applecups
1.1.20:rc1
applecups
1.1.20:rc2
applecups
1.1.20:rc3
applecups
1.1.20:rc4
applecups
1.1.20:rc5
applecups
1.1.20:rc6
applecups
1.1.21
applecups
1.1.21:rc1
applecups
1.1.21:rc2
applecups
1.1.22
applecups
1.1.22:rc1
applecups
1.1.22:rc2
applecups
1.1.23
applecups
1.1.23:rc1
applecups
1.2:b1
applecups
1.2:b2
applecups
1.2:rc1
applecups
1.2:rc2
applecups
1.2:rc3
applecups
1.2.0
applecups
1.2.1
applecups
1.2.2
applecups
1.2.3
applecups
1.2.4
applecups
1.2.5
applecups
1.2.6
applecups
1.2.7
applecups
1.2.8
applecups
1.2.9
applecups
1.2.10
applecups
1.2.11
applecups
1.2.12
applecups
1.3:b1
applecups
1.3:rc1
applecups
1.3:rc2
applecups
1.3.0
applecups
1.3.1
applecups
1.3.2
applecups
1.3.3
applecups
1.3.4
applecups
1.3.5
applecups
1.3.6
applecups
1.3.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bullseye
2.3.3op2-3+deb11u8
fixed
bullseye (security)
2.3.3op2-3+deb11u9
fixed
bookworm
2.4.2-3+deb12u7
fixed
bookworm (security)
2.4.2-3+deb12u8
fixed
sid
2.4.10-2
fixed
trixie
2.4.10-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
hardy
dne
gutsy
dne
feisty
dne
dapper
dne
cupsys
hardy
Fixed 1.3.7-1ubuntu3.1
released
gutsy
Fixed 1.3.2-1ubuntu7.8
released
feisty
Fixed 1.2.8-0ubuntu8.6
released
dapper
Fixed 1.2.2-0ubuntu0.6.06.11
released
Common Weakness Enumeration
References