CVE-2014-4337
cups-filters < 1.0.52 - Denial of Service via Crafted Packet Data in process_browse_data
Title source: llmDescription
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.
References (5)
Core 5
Core References
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1795.html
Permissions Required third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62044
Patch x_refsource_confirm
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7194
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68122
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2014/06/19/12
Scores
EPSS
0.0213
EPSS Percentile
84.4%
Details
CWE
CWE-119
Status
published
Products (1)
linuxfoundation/cups-filters
< 1.0.52
Published
Jun 22, 2014
Tracked Since
Feb 18, 2026