Out-of-bounds Write Affecting libcupsppdc1 package, versions <2.2.7-150000.3.51.2
Threat Intelligence
EPSS
0.1% (43rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES153-LIBCUPSPPDC1-5912763
- published 21 Sep 2023
- disclosed 20 Sep 2023
Introduced: 20 Sep 2023
CVE-2023-4504 Open this link in a new tabHow to fix?
Upgrade SLES:15.3 libcupsppdc1 to version 2.2.7-150000.3.51.2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcupsppdc1 package and not the libcupsppdc1 package as distributed by SLES.
See How to fix? for SLES:15.3 relevant fixed versions and status.
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
References
- https://www.suse.com/security/cve/CVE-2023-4504.html
- https://bugzilla.suse.com/1215204
- https://bugzilla.suse.com/1217457
- https://bugzilla.suse.com/1217553
- https://bugzilla.suse.com/1218317
- https://bugzilla.suse.com/1218347
- https://bugzilla.suse.com/1221585
- https://github.com/OpenPrinting/cups/releases/tag/v2.4.7
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678h
- https://github.com/OpenPrinting/libppd/security/advisories/GHSA-4f65-6ph5-qwh6
- https://takeonme.org/cves/CVE-2023-4504.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WHEJIYMMAIXU2EC35MGTB5LGGO2FFJE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WVS4I7JG3LISFPKTM6ADKJXXEPEEWBQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AMYDKIE4PSJDEMC5OWNFCDMHFGLJ57XG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2GSPQAFK2Z6L57TRXEKZDF42K2EVBH7/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00041.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXPVADB56NMLJWG4IZ3OZBNJ2ZOLPQJ6/
CVSS Scores
version 3.1