Back to Database
Status published
Medium
CVE-2004-1267
Buffer overflow in the ParseCommand function in hpgl-input.c in the...
Vulnerability Description
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1267
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2005-013.html
- http://tigger.uic.edu/~jlongs2/holes/cups.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10620
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18604
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:008
- http://www.redhat.com/support/errata/RHSA-2005-053.html
- https://usn.ubuntu.com/50-1/
- http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml
More from easy software products
View All →CVE-2008-1373
Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows...
Medium
5.8
CVE-2008-0597
Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions,...
Medium
5
CVE-2008-0596
Memory leak in CUPS before 1.1.22, and possibly other versions,...
Medium
5
CVE-2007-5849
Integer underflow in the asn1_get_string function in the SNMP back...
Critical
9.3
CVE-2005-3626
Xpdf, as used in products such as gpdf, kpdf, pdftohtml,...
Medium
5
Affected Vendor
easy software products
View all reports →Affected Software
cups, fedora core
Vulnerable Versions:
1.0.4, 1.0.4_8, 1.1.1, 1.1.4, 1.1.4_2, 1.1.4_3, 1.1.4_5, 1.1.6, 1.1.7, 1.1.10, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.19_rc5, 1.1.20, 1.1.21, 1.1.22_rc1, core_2.0, core_3.0
Timeline
Official Publish:
December 22nd, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.