Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-4504

Опубликовано: 21 сент. 2023
Источник: debian
EPSS Низкий

Описание

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cupsfixed2.4.2-6package
cupsfixed2.4.2-3+deb12u2bookwormpackage
cupsfixed2.3.3op2-3+deb11u4bullseyepackage
libppdnot-affectedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/09/20/3

  • https://takeonme.org/cves/CVE-2023-4504.html

  • Fixed by: https://github.com/OpenPrinting/cups/commit/2431caddb7e6a87f04ac90b5c6366ad268b6ff31 (v2.4.7)

  • Introduced after: https://github.com/OpenPrinting/libppd/commit/fae71641faa2d778e79245b788a90c0cd5d2cb4b (2.0b1)

  • Fixed by: https://github.com/OpenPrinting/libppd/commit/262c909ac5b8676d1c221584c5a760e5e83fae66

EPSS

Процентиль: 9%
0.00036
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
почти 2 года назад

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

CVSS3: 7
redhat
почти 2 года назад

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

CVSS3: 7
nvd
почти 2 года назад

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

CVSS3: 7
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.8
fstec
почти 2 года назад

Уязвимость функции scan_ps() библиотеки libppd сервера печати CUPS, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 9%
0.00036
Низкий