Bug 1235385 (CVE-2015-3258)

Summary: CVE-2015-3258 cups-filters: texttopdf heap-based buffer overflow
Product: [Other] Security Response Reporter: Stefan Cornelius <scorneli>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: carnil, security-response-team, slawomir, twaugh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
A heap-based buffer overflow was discovered in the way the texttopdf utility of cups-filter processed print jobs with a specially crafted line size. An attacker able to submit print jobs could use this flaw to crash texttopdf or, possibly, execute arbitrary code with the privileges of the "lp" user.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-11-20 05:04:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1194263, 1241242    
Bug Blocks: 1210268, 1235386    

Description Stefan Cornelius 2015-06-24 16:44:03 UTC
A heap-based buffer overflow was discovered in the way the texttopdf utility of cups-filters processed print jobs with a specially crafted line size. An attacker being able to submit print jobs could exploit this flaw to crash texttopdf or, possibly, execute arbitrary code with the privileges of the 'lp' user.

Acknowledgements:

This issue was discovered by Petr Sklenar of Red Hat.

Comment 1 Stefan Cornelius 2015-06-24 16:49:25 UTC
Patch:
https://bugzilla.redhat.com/attachment.cgi?id=993617&action=diff

Comment 2 Stefan Cornelius 2015-06-26 16:39:52 UTC
Public via/Patch:

http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7363

Fixed in cups-filters 1.0.70.

Comment 4 errata-xmlrpc 2015-11-19 12:08:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:2360 https://rhn.redhat.com/errata/RHSA-2015-2360.html