Name | CVE-2015-3258 |
Description | Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DLA-314-1, DSA-3303-1 |
NVD severity | high |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
cups (PTS) | stretch | 2.2.1-8+deb9u6 | fixed |
stretch (security) | 2.2.1-8+deb9u2 | fixed | |
buster | 2.2.10-6+deb10u4 | fixed | |
bullseye, sid | 2.3.3op2-3 | fixed | |
cups-filters (PTS) | stretch (security), stretch | 1.11.6-3+deb9u1 | fixed |
buster | 1.21.6-5 | fixed | |
bullseye, sid | 1.28.7-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
cups | source | squeeze | 1.4.4-7+squeeze10 | DLA-314-1 | ||
cups | source | (unstable) | 1.5.0-16 | |||
cups-filters | source | wheezy | 1.0.18-2.1+deb7u2 | DSA-3303-1 | ||
cups-filters | source | jessie | 1.0.61-5+deb8u1 | DSA-3303-1 | ||
cups-filters | source | (unstable) | 1.0.70-1 |
cups moved filters to separate package in 1.5.0-16
https://bugzilla.redhat.com/show_bug.cgi?id=1235385