ZeroHour

CVE-2023-4504

PoC ×3
CVSS 3.1
7.0 high
EPSS
<1%p50
Published
()
Modified
Description

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Vendors
openprintingfedoraprojectdebian
Products
cups, libppd, fedora, debian linux
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.