CVE-2023-4504
published 2023-09-21CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer…
PriorityP430high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.66%
47.6th percentile
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.3op2-3+deb11u4 | 2.3.3op2-3+deb11u4 |
| apple | cups | >= 0 < 2.4.2-3+deb12u2 | 2.4.2-3+deb12u2 |
| apple | cups | >= 0 < 2.4.2-6 | 2.4.2-6 |
| apple | cups | >= 0 < 2.4.2-6 | 2.4.2-6 |
| apple | macos_sequoia | — | — |
| debian | cups | < cups 2.4.2-3+deb12u2 (bookworm) | cups 2.4.2-3+deb12u2 (bookworm) |
| debian | debian_linux | — | — |
| debian | libppd | < cups 2.4.2-3+deb12u2 (bookworm) | cups 2.4.2-3+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_cups_2.3.3op2-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_cups_2.4.10-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cups_2.3.3op2-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cups_2.3.3op2-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openprinting | cups | < 2.4.6 | 2.4.6 |
| openprinting | cups | < 2.4.7 | 2.4.7 |
| openprinting | libppd | < d09348b | d09348b |
| openprinting | libppd | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-4504: macOS Sequoia 15
vendor_apple·2024-09-16·CVSS 7.0
CVE-2023-4504 [HIGH] CVE-2023-4504: macOS Sequoia 15
Apple Security Update: About the security content of macOS Sequoia 15
Product: macOS Sequoia
Version: 15
CVE: CVE-2023-4504
Component: CVE-2023-4504
Ubuntu
CUPS vulnerability
vendor_ubuntu·2023-09-21
CVE-2023-4504 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to crash or run programs if it opened a specially
crafted file.
USN-6391-1 fixed a vulnerability in CUPS. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libppd: Postscript Parsing Heap Overflow
vendor_redhat·2023-09-20·CVSS 7.0
CVE-2023-4504 [HIGH] CWE-122 libppd: Postscript Parsing Heap Overflow
libppd: Postscript Parsing Heap Overflow
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
A vulnerability was found in CUPS and libppd, where a failure to validate the length provided in an attacker-crafted PPD PostScript document can lead to a heap-based buffer overflow, causing a denial of service or, in some cases, execute arbitrary code, depending on how the application processes untrusted PPD files.
Statement: This vulnerability is rated as moderate because a heap-based buffer overflow in CUPS and libppd, caused by improper length validation in attacker-crafted PPD
Ubuntu
libppd vulnerability
vendor_ubuntu·2023-09-20
CVE-2023-4504 libppd vulnerability
Title: libppd vulnerability
Summary: libppd could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libppd incorrectly parsed certain Postscript
objects. If a user or automated system were tricked into printing a
specially crafted document, a remote attacker could use this issue to cause
libppd to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2023-09-20
CVE-2023-4504 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
vendor_msrc·2023-09-12·CVSS 7.0
CVE-2023-4504 [HIGH] CWE-787 OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
AHA: AHA
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.m
Debian
CVE-2023-4504: cups - Due to failure in validating the length provided by an attacker-crafted PPD Post...
vendor_debian·2023·CVSS 7.0
CVE-2023-4504 [HIGH] CVE-2023-4504: cups - Due to failure in validating the length provided by an attacker-crafted PPD Post...
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
Scope: local
bookworm: resolved (fixed in 2.4.2-3+deb12u2)
bullseye: resolved (fixed in 2.3.3op2-3+deb11u4)
forky: resolved (fixed in 2.4.2-6)
sid: resolved (fixed in 2.4.2-6)
trixie: resolved (fixed in 2.4.2-6)
OSV
CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffe
osv·2023-09-21·CVSS 7.0
CVE-2023-4504 [HIGH] CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffe
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/OpenPrinting/cups/releases/tag/v2.4.7https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678hhttps://github.com/OpenPrinting/libppd/security/advisories/GHSA-4f65-6ph5-qwh6https://lists.debian.org/debian-lts-announce/2023/09/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5WHEJIYMMAIXU2EC35MGTB5LGGO2FFJE/https://lists.fedoraproject.org/archives/list/[email protected]/message/5WVS4I7JG3LISFPKTM6ADKJXXEPEEWBQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/AMYDKIE4PSJDEMC5OWNFCDMHFGLJ57XG/https://lists.fedoraproject.org/archives/list/[email protected]/message/PXPVADB56NMLJWG4IZ3OZBNJ2ZOLPQJ6/https://lists.fedoraproject.org/archives/list/[email protected]/message/T2GSPQAFK2Z6L57TRXEKZDF42K2EVBH7/https://takeonme.org/cves/CVE-2023-4504.htmlhttp://seclists.org/fulldisclosure/2024/Sep/33https://github.com/OpenPrinting/cups/releases/tag/v2.4.7https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678hhttps://github.com/OpenPrinting/libppd/security/advisories/GHSA-4f65-6ph5-qwh6https://lists.debian.org/debian-lts-announce/2023/09/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5WHEJIYMMAIXU2EC35MGTB5LGGO2FFJE/https://lists.fedoraproject.org/archives/list/[email protected]/message/5WVS4I7JG3LISFPKTM6ADKJXXEPEEWBQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/AMYDKIE4PSJDEMC5OWNFCDMHFGLJ57XG/https://lists.fedoraproject.org/archives/list/[email protected]/message/PXPVADB56NMLJWG4IZ3OZBNJ2ZOLPQJ6/https://lists.fedoraproject.org/archives/list/[email protected]/message/T2GSPQAFK2Z6L57TRXEKZDF42K2EVBH7/https://takeonme.org/cves/CVE-2023-4504.html
2023-09-21
Published