Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47076

Опубликовано: 26 сент. 2024
Источник: redhat
CVSS3: 8.2

Описание

CUPS is a standards-based, open-source printing system, and libcupsfilters contains the code of the filters of the former cups-filters package as library functions to be used for the data format conversion tasks needed in Printer Applications. The cfGetPrinterAttributes5 function in libcupsfilters does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

A flaw was found in OpenPrinting CUPS. In certain conditions, a remote attacker can add a malicious printer or directly hijack an existing printer by replacing the valid IPP URL with a malicious one. Also, it is possible that due to a lack of validation of IPP attributes returned by the server, this issue allows attacker-controlled data to be used on the rest of the CUPS system.

Меры по смягчению последствий

See the security bulletin for a detailed mitigation procedure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cups-filtersNot affected
Red Hat Enterprise Linux 10libcupsfiltersNot affected
Red Hat Enterprise Linux 7.7 Advanced Update Supportcups-filtersFixedRHSA-2024:755102.10.2024
Red Hat Enterprise Linux 7 Extended Lifecycle Supportcups-filtersFixedRHSA-2024:755302.10.2024
Red Hat Enterprise Linux 8cups-filtersFixedRHSA-2024:746301.10.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportcups-filtersFixedRHSA-2024:746101.10.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportcups-filtersFixedRHSA-2024:750402.10.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicecups-filtersFixedRHSA-2024:750402.10.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionscups-filtersFixedRHSA-2024:750402.10.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportcups-filtersFixedRHSA-2024:762303.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2314253cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
10 месяцев назад

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

CVSS3: 8.6
nvd
10 месяцев назад

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

CVSS3: 8.6
debian
10 месяцев назад

CUPS is a standards-based, open-source printing system, and `libcupsfi ...

CVSS3: 6.8
fstec
11 месяцев назад

Уязвимость функции cfGetPrinterAttributes5 библиотеки libcupsfilters сервера печати CUPS, позволяющая нарушителю раскрыть защищаемую информацию

suse-cvrf
9 месяцев назад

Security update for cups-filters

8.2 High

CVSS3