A NULL pointer dereference issue exists in the _WriteProlog function of the texttops image filter. The return value from calloc is not checked. This may lead to a NULL pointer dereference. Since the offset from the pointer at which data is subsequently written is controlled by the user, this issue may lead to application termination or arbitrary code execution.
Created attachment 410579 [details] Proposed patch from Apple
Created attachment 412171 [details] updated patch for 1.3.7
Acknowledgements: Red Hat would like to thank the Apple Product Security team for responsibly reporting this issue. Upstream acknowledges regenrecht as the original reporter.
This is public now via the CUPS 1.4.4 release: http://cups.org/str.php?L3516 http://cups.org/articles.php?L596 They don't mention the CVE names, however.
Created cups tracking bugs for this issue Affects: fedora-all [bug 605399]
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Via RHSA-2010:0490 https://rhn.redhat.com/errata/RHSA-2010-0490.html
cups-1.4.4-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/cups-1.4.4-1.fc13
cups-1.4.4-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/cups-1.4.4-1.fc12
cups-1.4.4-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/cups-1.4.4-1.fc11
cups-1.4.4-4.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/cups-1.4.4-4.fc13
cups-1.4.4-4.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
cups-1.4.4-5.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
cups-1.4.4-5.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.