CVE-2007-5849

UNKNOWN
9.3CVSS
Published: 2007-12-19
Updated: 2025-04-09
AI Analysis

Description

Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-189

Metadata

Primary Vendor
EASY_SOFTWARE_PRODUCTS
Published
12/19/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

easy_software_products : cupseasy_software_products : cupseasy_software_products : cupseasy_software_products : cupseasy_software_products : cups

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-5849 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com