Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:7346

Опубликовано: 30 сент. 2024
Источник: rocky
Оценка: Important

Описание

Important: cups-filters security update

The cups-filters package contains back ends, filters, and other software that was once part of the core Common UNIX Printing System (CUPS) distribution but is now maintained independently.

Security Fix(es):

  • cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source ()

  • cups-filters: libcupsfilters: cfGetPrinterAttributes API does not perform sanitization on returned IPP attributes (CVE-2024-47076)

  • cups: libppd: remote command injection via attacker controlled data in PPD file ()

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
cups-filtersx86_6417.el9_4cups-filters-1.28.7-17.el9_4.x86_64.rpm
cups-filters-libsx86_6417.el9_4cups-filters-libs-1.28.7-17.el9_4.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
8 месяцев назад

Important: cups-filters security update

oracle-oval
9 месяцев назад

ELSA-2024-7463: cups-filters security update (IMPORTANT)

oracle-oval
9 месяцев назад

ELSA-2024-7346: cups-filters security update (IMPORTANT)

oracle-oval
7 месяцев назад

ELSA-2024-7553: cups-filters security update (IMPORTANT)

CVSS3: 8.6
ubuntu
9 месяцев назад

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.