Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
https://bugzilla.redhat.com/show_bug.cgi?id=1027547
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741333
http://www.ubuntu.com/usn/USN-2143-1
http://www.securityfocus.com/bid/66601
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7175