CVE-2008-3641
high · 10The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
10
CVSS
24.1%
EPSS (exploit prob.)
98th
EPSS percentile
2008-10-10
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-399
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | cups | <= 1.3.8 |
| apple | cups | 1.1 |
| apple | cups | 1.1.1 |
| apple | cups | 1.1.2 |
| apple | cups | 1.1.3 |
| apple | cups | 1.1.4 |
| apple | cups | 1.1.5 |
| apple | cups | 1.1.5-1 |
| apple | cups | 1.1.5-2 |
| apple | cups | 1.1.6 |
| apple | cups | 1.1.6-1 |
| apple | cups | 1.1.6-2 |
| apple | cups | 1.1.6-3 |
| apple | cups | 1.1.7 |
| apple | cups | 1.1.8 |
| apple | cups | 1.1.9 |
| apple | cups | 1.1.9-1 |
| apple | cups | 1.1.10 |
| apple | cups | 1.1.10-1 |
| apple | cups | 1.1.11 |
| apple | cups | 1.1.12 |
| apple | cups | 1.1.13 |
| apple | cups | 1.1.14 |
| apple | cups | 1.1.15 |
| apple | cups | 1.1.16 |
| apple | cups | 1.1.17 |
| apple | cups | 1.1.18 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.19 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
| apple | cups | 1.1.20 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html
- http://secunia.com/advisories/32084
- http://secunia.com/advisories/32222
- http://secunia.com/advisories/32226
- http://secunia.com/advisories/32284
- http://secunia.com/advisories/32292
- http://secunia.com/advisories/32316
- http://secunia.com/advisories/32331
- http://secunia.com/advisories/33085
- http://secunia.com/advisories/33111
- http://secunia.com/advisories/33568
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-261088-1
- http://support.apple.com/kb/HT3216
- http://support.avaya.com/elmodocs2/security/ASA-2008-470.htm
- http://www.cups.org/articles.php?L575
- http://www.cups.org/str.php?L2911
- http://www.debian.org/security/2008/dsa-1656
- http://www.gentoo.org/security/en/glsa/glsa-200812-11.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:211
- http://www.redhat.com/support/errata/RHSA-2008-0937.html
- http://www.securityfocus.com/archive/1/497221/100/0/threaded
- http://www.securityfocus.com/bid/31681
- http://www.securityfocus.com/bid/31688
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-3641