<title>CUPS: Integer overflow vulnerability</title>
A vulnerability in CUPS might allow for the execution of arbitrary code or
a Denial of Service.
<announced>April 18, 2008</announced>
<revised>April 18, 2008: 01</revised>
<access>remote, local</access>
CUPS provides a portable printing layer for UNIX-based operating
Thomas Pollet reported a possible integer overflow vulnerability in the
PNG image handling in the file filter/image-png.c.
A malicious user might be able to execute arbitrary code with the
privileges of the user running CUPS (usually lp), or cause a Denial of
Service by sending a specially crafted PNG image to the print server.
The vulnerability is exploitable via the network if CUPS is sharing
printers remotely.
All CUPS users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=net-print/cups-1.2.12-r8&quot;</code>
<uri link="">CVE-2008-1722</uri>
