HIGH · 7.5

CVE-2008-0755

Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier...

Vulnerability Description

Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute arbitrary code via format string specifiers in the queue name in a request.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Cyan SoftCyanprintip Basic<= 4.10.1030
Cyan SoftCyanprintip Easy Opi<= 4.10.1030
Cyan SoftCyanprintip Professional<= 4.10.1030
Cyan SoftCyanprintip Standard<= 4.10.940
Cyan SoftCyanprintip Workstation<= 4.10.836
Cyan SoftOpium4 Opi Server<= 4.10.1028

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-0755?

CVE-2008-0755 is a vulnerability with a CVSS score of 7.5 (HIGH). Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier...

How severe is CVE-2008-0755?

CVE-2008-0755 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0755?

Check the references section above for vendor advisories and patch information. Affected products include: Cyan Soft Cyanprintip Basic, Cyan Soft Cyanprintip Easy Opi, Cyan Soft Cyanprintip Professional, Cyan Soft Cyanprintip Standard, Cyan Soft Cyanprintip Workstation.