Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24853
HistoryApr 10, 2020 - 1:07 a.m.

Remote Code Execution (RCE)

2020-04-1001:07:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
45

0.018 Low

EPSS

Percentile

88.1%

cups is vulnerable to remote code execution (RCE). The attack exists because of LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS.

References