mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-19 17:31:42 +00:00
409 lines
16 KiB
JSON
409 lines
16 KiB
JSON
{
|
|
"id": "CVE-2013-6475",
|
|
"sourceIdentifier": "secalert@redhat.com",
|
|
"published": "2014-03-14T15:55:05.540",
|
|
"lastModified": "2024-11-21T01:59:18.070",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "M\u00faltiples desbordamientos de enteros en (1) OPVPOutputDev.cxx y (2) oprs/OPVPSplash.cxx en el filtro pdftoopvp en CUPS y cups-filters anterior a 1.0.47 permiten a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de un archive de PDF manipulado, lo que provoca un desbordamiento de buffer basado en memoria din\u00e1mica."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"baseScore": 6.8,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "PARTIAL"
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 6.4,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-189"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*",
|
|
"matchCriteriaId": "7118F616-25CA-4E34-AA13-4D14BB62419F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*",
|
|
"matchCriteriaId": "F5D324C4-97C7-49D3-A809-9EAD4B690C69"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E2076871-2E80-4605-A470-A41C1A8EC7EE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7F61F047-129C-41A6-8A27-FFCBB8563E91"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4C8919F1-CD33-437E-9627-69352B276BA3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "20294CE7-12C8-43CA-A702-5ED2A3044FFC"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "1.0.46",
|
|
"matchCriteriaId": "96BE9065-DBB6-476F-94E4-9E1ABFE12B6C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A2537957-4C48-4EAE-8ABE-7007609D470E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "AB423F2E-D982-4E4E-8BC4-A9422EED0E53"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "79EE8950-8167-40C5-B590-D7E7D8CE8684"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "845FC6CC-0419-4E2C-89E9-2E3B4E862DF5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F3D38380-F381-4C30-9997-5B0AF4E90084"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C007E84B-0215-41DA-90C6-A7AD13CEC2F1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "31A82F3D-2F83-4C01-AF26-4F3D92B56F50"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D08737A6-1CCA-435C-9A73-1ECD28F4B38A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "ED2C7719-DC78-4D79-B98F-6E9012059D8D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.9:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FBBAD866-D5D9-4CB9-8ED0-DF308A5F6686"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "549FDAD0-C44C-420E-8482-E4C1CF1AC806"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "24595CDE-84CD-4E7F-B583-3A95CD739EEB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.12:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "77FC9AB9-1C09-41E3-BCDD-420F0EFDFB9C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.13:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "57D9EF6E-464B-49AE-B3B9-E6A18C97D44B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2148B414-A59B-4C4E-8274-308D77E67BFE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.15:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0B8E1B50-FD96-4DF1-9DD3-A80E3BC8A9DB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.16:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7A4FFF7B-FB25-4CAD-A836-E003F1D8FFBF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.17:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "30C5C5FF-FD58-4068-AD29-4E0B6B9453C2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.18:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6B179FE0-A32B-4BB5-8B94-837B31097AAC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.19:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4EF65925-90E3-4D80-A768-9F1A232FF6C6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.20:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9D41125E-5173-4942-AD13-A1E89F966C38"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.21:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6E33FB77-5E09-424B-89CD-B58F1C3E443E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.22:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "63529640-E326-4BAE-81B8-A1DDB7212944"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.23:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "59F87B81-6EC5-40C2-9506-519F91DAF7F1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.24:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FC988F76-C53C-4AE8-AFF2-1ADFA55E4D91"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.25:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "62C771DD-9569-4688-BA5F-D292D81E2FF5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.26:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "29F35F4F-86BB-42E6-B5DA-610266232C61"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.27:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "63CD4E64-D224-4BD6-B6B8-7FEABCC6A345"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.28:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C9388F6C-59C2-49DE-8FF7-68AA6033AECD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.29:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EBE35CE5-81F1-450E-8F14-D0967C9B01BD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.30:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A9771D47-3F6E-441A-BB32-C1F0D022B10A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.31:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0A054DB2-3CE6-4E05-8D1B-000ABF6635A9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.32:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D9C1C1B0-E520-44EA-8CE6-BD111EF7F885"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.33:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B7408F05-425B-4824-86EE-B54B51457573"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.34:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F10EC538-4671-4583-A70D-BD2A0B653546"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.35:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "29F97CA8-BF93-4A54-A96F-3AD097CB74A6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.36:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "33EE31E7-A845-479F-A765-237824CB79C0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.37:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2A1FB206-A3E3-443C-B82E-9DDE33BD533D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.38:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "83CFEE4A-A07F-4B13-8D94-FEDC709F51D5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.39:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3159BD60-433B-4409-B4B6-BDEC8542B218"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.40:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4D10B33C-077A-4055-B47B-13115A05F0DA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.41:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3BF5B05C-7C56-4FB1-821D-5A919E56C823"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.42:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "68650F82-F655-4008-85EF-E86C02D9944D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.43:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "23CA8354-40A7-4E01-AA8A-8200A34EA2BD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.44:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "26EA706E-DE8C-404F-BE45-99E0E8C1D0BF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:linuxfoundation:cups-filters:1.0.45:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BC53B1B4-00F9-48B3-903F-D49F1E66668D"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7176",
|
|
"source": "secalert@redhat.com",
|
|
"tags": [
|
|
"Patch"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.debian.org/security/2014/dsa-2875",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.debian.org/security/2014/dsa-2876",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/66166",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.ubuntu.com/usn/USN-2143-1",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.ubuntu.com/usn/USN-2144-1",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1027550",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7176",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Patch"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.debian.org/security/2014/dsa-2875",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.debian.org/security/2014/dsa-2876",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/66166",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.ubuntu.com/usn/USN-2143-1",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.ubuntu.com/usn/USN-2144-1",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1027550",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |