>> CUPS PNG Filter Data Handling Integer Overflow Vulnerabilities
Title : CUPS PNG Filter Data Handling Integer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1226 CVE ID : CVE-2008-1722
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-15
Technical Description
Multiple vulnerabilities have been identified in CUPS, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by integer overflow errors in the PNG Image Filter (filter/image-png.c) that does not validate the "CUPS_IMAGE_MAX_WIDTH" and "CUPS_IMAGE_MAX_HEIGHT" values, which could be exploited by attackers to crash an affected application or execute arbitrary code.