Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-87875

Опубликовано: 09 сент. 2026
Источник: debian
EPSS Низкий

Описание

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cupsunfixedpackage

Примечания

  • https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq

EPSS

Процентиль: 25%
0.00324
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 дней назад

(The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a sour ...)

CVSS3: 4.3
redhat
7 дней назад

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

CVSS3: 4.3
nvd
6 дней назад

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

EPSS

Процентиль: 25%
0.00324
Низкий