Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-64524

Опубликовано: 20 нояб. 2025
Источник: debian
EPSS Низкий

Описание

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. This issue can be exploited to trigger memory corruption, potentially leading to arbitrary code execution. This issue has been patched via commit 956283c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cups-filtersfixed1.28.17-7package
cups-filtersfixed1.28.17-6+deb13u1trixiepackage
cups-filtersfixed1.28.17-3+deb12u2bookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2025/11/20/1

  • https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq44-2q5p-x3hv

  • Fixed by: https://github.com/OpenPrinting/cups-filters/commit/0fe46c511e81062575b05936f804eb18c9f0a011 (master)

  • Fixed by: https://github.com/OpenPrinting/cups-filters/commit/b03866fd2e251a6d822a5e8c807c8d47b4d2dce2 (1.x branch)

EPSS

Процентиль: 7%
0.00026
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. This issue can be exploited to trigger memory corruption, potentially leading to arbitrary code execution. This issue has been patched via commit 956283c.

CVSS3: 3.3
nvd
3 месяца назад

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. This issue can be exploited to trigger memory corruption, potentially leading to arbitrary code execution. This issue has been patched via commit 956283c.

suse-cvrf
2 месяца назад

Security update for cups-filters

suse-cvrf
3 месяца назад

Security update for cups-filters

EPSS

Процентиль: 7%
0.00026
Низкий