cbcvebase.
CVE-2023-4504
published 2023-09-21

CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer…

high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Affected

23 ranges
VendorProductVersion rangeFixed in
applecups>= 0 < 2.3.3op2-3+deb11u42.3.3op2-3+deb11u4
applecups>= 0 < 2.4.2-3+deb12u22.4.2-3+deb12u2
applecups>= 0 < 2.4.2-62.4.2-6
applecups>= 0 < 2.4.2-62.4.2-6
applemacos_sequoia
debiancups< cups 2.4.2-3+deb12u2 (bookworm)cups 2.4.2-3+deb12u2 (bookworm)
debiandebian_linux
debianlibppd< cups 2.4.2-3+deb12u2 (bookworm)cups 2.4.2-3+deb12u2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_cups_2.3.3op2-6_on_azure_linux_3.0
msrcazl3_cups_2.4.10-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cups_2.3.3op2-7_on_cbl_mariner_2.0
msrccbl2_cups_2.3.3op2-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
openprintingcups< 2.4.62.4.6
openprintingcups< 2.4.72.4.7
openprintinglibppd< d09348bd09348b
openprintinglibppd

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.0HIGH