Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
CVSS Vector
AV:N/AC:M/Au:N/C:C/I:C/A:CApple Mac Os X
OSApple10.5.2Apple Mac Os X Server
OSApple10.5.2Cups
APPCups1.3.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References
Related vulnerabilities
CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS
CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
CVE-2015-5119CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — use-after-free w klasie ByteArray umożliwia RCE