CVE-2014-9679
Title: Apple Cups Memory Corruption
Memory Corruption
Proof Of Concept
No public PoC currently indexed for CVE-2014-9679.
CWE Category
CWE-119
Published Date
Feb 19, 2015
Modified Date
May 06, 2026
Exploit Status
Not Found
Score
6.8
CVSS v2.0
Exploit Probability (EPSS)
5.93%
Vulnerability Summary
CVE-2014-9679: Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
Impacted Vendors
Reference Links
http://advisories.mageia.org/MGASA-2015-0067.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150171.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150177.html
http://lists.opensuse.org/opensuse-updates/2015-02/msg00098.html
http://rhn.redhat.com/errata/RHSA-2015-1123.html
http://www.debian.org/security/2015/dsa-3172
http://www.mandriva.com/security/advisories?name=MDVSA-2015:049
http://www.mandriva.com/security/advisories?name=MDVSA-2015:108
http://www.openwall.com/lists/oss-security/2015/02/10/15
http://www.openwall.com/lists/oss-security/2015/02/12/12
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/72594
http://www.securitytracker.com/id/1031776
http://www.ubuntu.com/usn/USN-2520-1
https://security.gentoo.org/glsa/201607-06
https://www.cups.org/str.php?L4551
http://advisories.mageia.org/MGASA-2015-0067.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150171.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150177.html
http://lists.opensuse.org/opensuse-updates/2015-02/msg00098.html
http://rhn.redhat.com/errata/RHSA-2015-1123.html
http://www.debian.org/security/2015/dsa-3172
http://www.mandriva.com/security/advisories?name=MDVSA-2015:049
http://www.mandriva.com/security/advisories?name=MDVSA-2015:108
http://www.openwall.com/lists/oss-security/2015/02/10/15
http://www.openwall.com/lists/oss-security/2015/02/12/12
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/72594
http://www.securitytracker.com/id/1031776
http://www.ubuntu.com/usn/USN-2520-1
https://security.gentoo.org/glsa/201607-06
https://www.cups.org/str.php?L4551
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:P/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2014-9679 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Stack
No specific products linked.