Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23843
HistoryApr 10, 2020 - 12:37 a.m.

Arbitrary Code Execution

2020-04-1000:37:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.018 Low

EPSS

Percentile

88.3%

cups is vulnerable to arbitrary code execution. An integer overflow flaw, leading to a heap-based buffer overflow, was discovered in the Tagged Image File Format (TIFF) decoding routines used by the CUPS image-converting filters, β€œimagetops” and β€œimagetoraster”. An attacker could create a malicious TIFF file that could, potentially, execute arbitrary code as the β€œlp” user if the file was printed.

References