ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “Zero Day Initiative discloses two PAPPL buffer overflows: unauthenticated RCE rated CVSS 9.8 and local privilege escalation rated CVSS 7.8” — merged summary and timeline →

ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability

highAdvisoryimportance 35
AI summary · glm-5.3-flash

ZDI-26-656: Unauthenticated heap-based buffer overflow in PAPPL job processing allows remote code execution, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-656 for PAPPL, the open-source printer application framework. A heap-based buffer overflow in job processing allows remote attackers to execute arbitrary code with no authentication required. ZDI assigned a CVSS 9.8 rating. No CVE identifier was listed in the advisory text.

  • Unauthenticated remote code execution in PAPPL job processing
  • Heap-based buffer overflow with CVSS 9.8
  • Disclosure coordinated by the Zero Day Initiative
ProductsPAPPL
OrganizationsZero Day Initiative
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PAPPL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.

This source does not provide full text. Read it at zerodayinitiative.com.