{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:12:47Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20071031-CVE-2007-4351","slug":"cisco-sa-20071031-cve-2007-4351","vendor":"Cisco","title":"Common UNIX Printing System IPP Tags Memory Corruption Vulnerability","summary":"The Common UNIX Printing System (CUPS) versions 1.3.3 and prior contain a vulnerability that can allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or execute arbitrary code with the privileges of the user. The vulnerability exists in the ippReadIO()&nbsp;function when processing Internet Printing Protocol (IPP) tags.&nbsp; The function causes an off-by-one error when allocating space.&nbsp; An unauthenticated, remote attacker could send a request with crafted tags to overwrite one byte on the stack with a zero.&nbsp; The attacker could crash the daemon or possibly execute arbitrary code. The vendor has confirmed this vulnerability in release notes and released&nbsp;an updated version. The vulnerability requires the attacker to connect to the IPP TCP port to perform an attack.&nbsp; However, the default configuration of CUPS does not allow remote hosts to connect to this port.&nbsp; This configuration should mitigate the potential for this attack.&nbsp; IT departments that deploy and use CUPS without changing the default configuration may not be at risk. The severity of the impact will vary depending on the system on which CUPS is deployed.&nbsp; If this system is used for multiple services, a DoS condition could cause other services besides the CUPS service to crash, which may affect other users and departments.&nbsp; If code execution is accomplished, it will most likely be in the context of the CUPS user.&nbsp; This user probably has limited privileges.","severity":"Medium","published_at":"2007-10-31T17:40:08Z","updated_at":"2007-10-31T17:40:08Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20071031-CVE-2007-4351","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20071031-CVE-2007-4351/csaf/Cisco-SA-20071031-CVE-2007-4351.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.07377},"cves":[{"id":"CVE-2007-4351","kev":false,"epss":{"score":0.07377,"percentile":0.93739,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco Wide Area Application Services (WAAS)","slug":"cisco-wide-area-application-services-waas","vendor":"Cisco"},"cve":{"id":"CVE-2007-4351"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:26:15Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Wide Area Application Services (WAAS)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.07377,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2007-10-31T17:40:08Z","updated_at":"2007-10-31T17:40:08Z","advisory_updated_at":"2007-10-31T17:40:08Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20071031-CVE-2007-4351","row_display_order":1}]}