Debian DSA-1625-1 : cupsys - buffer overflows

This script is Copyright (C) 2008-2013 Tenable Network Security, Inc.


Synopsis :

The remote Debian host is missing a security-related update.

Description :

Several remote vulnerabilities have been discovered in the Common Unix
Printing System (CUPS). The Common Vulnerabilities and Exposures
project identifies the following problems :

- CVE-2008-0053
Buffer overflows in the HP-GL input filter allowed to
possibly run arbitrary code through crafted HP-GL files.

- CVE-2008-1373
Buffer overflow in the GIF filter allowed to possibly
run arbitrary code through crafted GIF files.

- CVE-2008-1722
Integer overflows in the PNG filter allowed to possibly
run arbitrary code through crafted PNG files.

See also :

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476305
http://security-tracker.debian.org/tracker/CVE-2008-0053
http://security-tracker.debian.org/tracker/CVE-2008-1373
http://security-tracker.debian.org/tracker/CVE-2008-1722
http://www.debian.org/security/2008/dsa-1625

Solution :

Upgrade the cupsys package.

For the stable distribution (etch), these problems have been fixed in
version 1.2.7-4etch4 of package cupsys.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Family: Debian Local Security Checks

Nessus Plugin ID: 33774 (debian_DSA-1625.nasl)

Bugtraq ID:

CVE ID: CVE-2008-0053
CVE-2008-1373
CVE-2008-1722