CVE-2002-1369

NameCVE-2002-1369
Descriptionjobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-232

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cups (PTS)bullseye2.3.3op2-3+deb11u8fixed
bullseye (security)2.3.3op2-3+deb11u10fixed
bookworm2.4.2-3+deb12u8fixed
bookworm (security)2.4.2-3+deb12u9fixed
trixie2.4.10-3fixed
trixie (security)2.4.10-3+deb13u1fixed
forky2.4.10-4fixed
sid2.4.14-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cupssource(unstable)1.1.18-1
cupsyssourcewoody1.1.14-4.3DSA-232
cupsyssource(unstable)1.1.18-1

Search for package or bug name: Reporting problems