Ubuntu Security Notice 539-1 – Alin Rad Pop discovered that CUPS did not correctly validate buffer lengths when processing IPP tags. Remote attackers successfully exploiting this vulnerability would gain access to the non-root CUPS user in Ubuntu 6.06 LTS, 6.10, and 7.04. In Ubuntu 7.10, attackers would be isolated by the AppArmor CUPS profile.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60706/USN-539-1.txt
Source: https://packetstormsecurity.com/files/60706/Ubuntu-Security-Notice-539-1.html

