ID

VAR-200212-0655


CVE

CVE-2002-1368


TITLE

CUPS of memcpy() Service disruption by handling negative values in functions (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2002-000332

DESCRIPTION

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding. ------------ This vulnerability information is a summary of multiple vulnerabilities released at the same time. Please note that the contents of vulnerability information other than the title are included. ------------ Common Unix Printing System (CUPS) Some UNIX Included in the UNIX Can be used universally in the environment Internet Printing Protocol version 1.1 (IPP/1.1) Is a printing system that supports Red Hat Linux 7.3 as well as 8.0 It is also bundled with. this CUPS Has the following security issues: still, Red Hat Linux Then CUPS Is disabled in the default installation. 1. Overflow due to overflow of integer digits * [CAN-2002-1383] CUPS There are a few problems with overflowing integer digits. For example, HTTP By exploiting this issue through the interface, a remote attacker can CUPSd Execute permission ( A user lp) Can execute arbitrary code. 2. Resource race condition for temporary file generation processing (race condition) Problem * [CAN-2002-1366] CUPS Is /etc/cups/certs/ less than pid ( Generation time CUPS Process ID) Creates a temporary file with a file name of, so a local attacker can predict how the temporary file name is determined. Therefore, by creating a file with the same name as the temporary file that points to the intended file, root Any file can be overwritten or created with authority. In order to execute this attack, 1. In advance, lp User rights are required. 3. Printer addition mechanism / Problems with the access control function * [CAN-2002-1367] Malicious maliciously created remotely UDP Packet CUPS By sending to, you can bypass the authentication and add a printer. Furthermore, there is a problem that the access control mechanism of the printer addition mechanism neglects the validity check. The added printer information is root Since it is interpreted by the authority, any print can be added by using these problems together. As a result, local attackers root Elevation to privilege is possible. 4. Intentionally created HTTP By communication CUPSd That crashes [CAN-2002-1368] CUPS Then IPP To accept connections on the backend HTTP server (CUPSd) Is included. To restore normal operation CUPSd Needs to be restarted. 5. strncat Problem of buffer overflow caused by function [CAN-2002-1369] CUPS Has a buffer overflow problem when receiving a printer job with a specific attribute value. By using this issue, a remote attacker can root It is possible to execute arbitrary code with authority. To take advantage of this issue, 3. Need to take advantage of the problem. 6.GIF Problems when handling file formats [CAN-2002-1371] CUPS In GIF Width in the part that handles format files (width) There is a problem with the process of validating the value of. For this reason, remote attackers are deliberately assembled (width) But '0' Is GIF Overwrite the allocated memory contents by interpreting the format file, CUPS An arbitrary code may be executed with the execution right. 7. File descriptor issues with sockets and files * [CAN-2002-1372] CUPS Has a problem that does not properly close file descriptors for sockets and files. For this reason, local attackers can use this issue to cause memory leaks, CUPS It is possible to put the entire system running in a service out of service state.Please refer to the “Overview” for the impact of this vulnerability. A vulnerability has been reported for CUPS that if exploited may result in a DoS or the execute of code on affected systems. An attacker can exploit this vulnerability by connecting to a vulnerable system and issuing malformed HTTP headers with a negative value for some fields. When the cupsd service receives this request, it will crash. This vulnerability is very similar to the issue described in BID 5033. It may be very likely that this vulnerability may be exploited to execute malicious attacker-supplied code on BSD, and possibly other, platforms. *** January 05, 2003 There are reports of this vulnerability being actively exploited in the wild. Vulnerable users are advised to update immediately

Trust: 1.98

sources: NVD: CVE-2002-1368 // JVNDB: JVNDB-2002-000332 // BID: 6437 // VULHUB: VHN-5753

AFFECTED PRODUCTS

vendor:easy productsmodel:cupsscope:eqversion:1.1.4_2

Trust: 1.6

vendor:easy productsmodel:cupsscope:eqversion:1.1.13

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.2

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.6

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.4

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.10

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.0.4_8

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.4_3

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.4_5

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.14

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.17

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.7

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.0.4

Trust: 1.0

vendor:easy productsmodel:cupsscope:eqversion:1.1.1

Trust: 1.0

vendor:red hatmodel:linuxscope:eqversion:7.3

Trust: 0.8

vendor:red hatmodel:linuxscope:eqversion:8.0

Trust: 0.8

vendor:easymodel:software products cupsscope:eqversion:1.1.17

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.16

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.15

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.14

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.13

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.12

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.10

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.7

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.6

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.4-5

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.4-3

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.4-2

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.4

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.1.1

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.0.4-8

Trust: 0.3

vendor:easymodel:software products cupsscope:eqversion:1.0.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2

Trust: 0.3

vendor:easymodel:software products cupsscope:neversion:1.1.18

Trust: 0.3

vendor:applemodel:mac osscope:neversion:x10.2.3

Trust: 0.3

sources: BID: 6437 // JVNDB: JVNDB-2002-000332 // CNNVD: CNNVD-200212-076 // NVD: CVE-2002-1368

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1368
value: HIGH

Trust: 1.0

NVD: CVE-2002-1368
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200212-076
value: HIGH

Trust: 0.6

VULHUB: VHN-5753
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-1368
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-5753
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5753 // JVNDB: JVNDB-2002-000332 // CNNVD: CNNVD-200212-076 // NVD: CVE-2002-1368

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1368

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-076

TYPE

Boundary Condition Error

Trust: 0.9

sources: BID: 6437 // CNNVD: CNNVD-200212-076

CONFIGURATIONS

sources: JVNDB: JVNDB-2002-000332

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-5753

PATCH

title:RHSA-2002:295url:https://rhn.redhat.com/errata/RHSA-2002-295.html

Trust: 0.8

title:RHSA-2002:295url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2002-295J.html

Trust: 0.8

sources: JVNDB: JVNDB-2002-000332

EXTERNAL IDS

db:NVDid:CVE-2002-1368

Trust: 2.8

db:BIDid:6437

Trust: 2.2

db:SECUNIAid:7858

Trust: 1.1

db:SECUNIAid:7756

Trust: 1.1

db:SECUNIAid:9325

Trust: 1.1

db:SECUNIAid:7913

Trust: 1.1

db:SECUNIAid:7803

Trust: 1.1

db:SECUNIAid:7843

Trust: 1.1

db:SECUNIAid:7907

Trust: 1.1

db:SECUNIAid:7794

Trust: 1.1

db:SECUNIAid:8080

Trust: 1.1

db:BIDid:6435

Trust: 0.8

db:BIDid:6439

Trust: 0.8

db:BIDid:6434

Trust: 0.8

db:BIDid:6433

Trust: 0.8

db:BIDid:6440

Trust: 0.8

db:BIDid:6436

Trust: 0.8

db:BIDid:6438

Trust: 0.8

db:JVNDBid:JVNDB-2002-000332

Trust: 0.8

db:CNNVDid:CNNVD-200212-076

Trust: 0.7

db:EXPLOIT-DBid:22106

Trust: 0.1

db:SEEBUGid:SSVID-75917

Trust: 0.1

db:VULHUBid:VHN-5753

Trust: 0.1

sources: VULHUB: VHN-5753 // BID: 6437 // JVNDB: JVNDB-2002-000332 // CNNVD: CNNVD-200212-076 // NVD: CVE-2002-1368

REFERENCES

url:http://www.securityfocus.com/bid/6437

Trust: 1.9

url:ftp://ftp.sco.com/pub/security/openlinux/cssa-2003-004.0.txt

Trust: 1.1

url:http://www.debian.org/security/2003/dsa-232

Trust: 1.1

url:http://www.mandriva.com/security/advisories?name=mdksa-2003:001

Trust: 1.1

url:http://www.idefense.com/advisory/12.19.02.txt

Trust: 1.1

url:http://www.redhat.com/support/errata/rhsa-2002-295.html

Trust: 1.1

url:http://secunia.com/advisories/7756/

Trust: 1.1

url:http://secunia.com/advisories/7794

Trust: 1.1

url:http://secunia.com/advisories/7803

Trust: 1.1

url:http://secunia.com/advisories/7843

Trust: 1.1

url:http://secunia.com/advisories/7858

Trust: 1.1

url:http://secunia.com/advisories/7907

Trust: 1.1

url:http://secunia.com/advisories/7913/

Trust: 1.1

url:http://secunia.com/advisories/8080/

Trust: 1.1

url:http://secunia.com/advisories/9325/

Trust: 1.1

url:http://www.novell.com/linux/security/advisories/2003_002_cups.html

Trust: 1.1

url:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/10909

Trust: 1.1

url:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=104032149026670&w=2

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2002-1368

Trust: 0.8

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2002-1368

Trust: 0.8

url:http://www.securityfocus.com/bid/6438

Trust: 0.8

url:http://www.securityfocus.com/bid/6440

Trust: 0.8

url:http://www.securityfocus.com/bid/6439

Trust: 0.8

url:http://www.securityfocus.com/bid/6434

Trust: 0.8

url:http://www.securityfocus.com/bid/6433

Trust: 0.8

url:http://www.securityfocus.com/bid/6435

Trust: 0.8

url:http://www.securityfocus.com/bid/6436

Trust: 0.8

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

url:/archive/1/304031

Trust: 0.3

url:/archive/1/304265

Trust: 0.3

url:http://marc.info/?l=bugtraq&m=104032149026670&w=2

Trust: 0.1

url:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702

Trust: 0.1

sources: VULHUB: VHN-5753 // BID: 6437 // JVNDB: JVNDB-2002-000332 // NVD: CVE-2002-1368

CREDITS

Discovered by zen-parse.

Trust: 0.9

sources: BID: 6437 // CNNVD: CNNVD-200212-076

SOURCES

db:VULHUBid:VHN-5753
db:BIDid:6437
db:JVNDBid:JVNDB-2002-000332
db:CNNVDid:CNNVD-200212-076
db:NVDid:CVE-2002-1368

LAST UPDATE DATE

2024-08-14T13:51:24.167000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5753date:2017-07-11T00:00:00
db:BIDid:6437date:2009-07-11T19:16:00
db:JVNDBid:JVNDB-2002-000332date:2007-04-01T00:00:00
db:CNNVDid:CNNVD-200212-076date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1368date:2017-07-11T01:29:14.367

SOURCES RELEASE DATE

db:VULHUBid:VHN-5753date:2002-12-26T00:00:00
db:BIDid:6437date:2002-12-19T00:00:00
db:JVNDBid:JVNDB-2002-000332date:2007-04-01T00:00:00
db:CNNVDid:CNNVD-200212-076date:2002-12-26T00:00:00
db:NVDid:CVE-2002-1368date:2002-12-26T05:00:00