Lucene search

K
cve[email protected]CVE-2008-0047
HistoryMar 18, 2008 - 11:44 p.m.

CVE-2008-0047

2008-03-1823:44:00
CWE-119
web.nvd.nist.gov
44
cve-2008-0047
cups
buffer overflow
remote code execution
printer sharing
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.835 High

EPSS

Percentile

98.5%

Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.

Affected configurations

NVD
Node
applemac_os_xMatch10.5.2
OR
applemac_os_x_serverMatch10.5.2
AND
cupscupsMatch1.3.5
CPENameOperatorVersion
cups:cupscupseq1.3.5

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.835 High

EPSS

Percentile

98.5%