ZeroHour
ZDI Published Advisoriespublished ()ingested 1
Part of a story covered by 2 sources: “Zero Day Initiative discloses two PAPPL buffer overflows: unauthenticated RCE rated CVSS 9.8 and local privilege escalation rated CVSS 7.8” — merged summary and timeline →

ZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 25
AI summary · glm-5.3-flash

ZDI-26-655: Stack-based buffer overflow in PAPPL printer IPP processing enables local privilege escalation, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-655 for PAPPL. A stack-based buffer overflow in printer IPP processing allows local attackers to escalate privileges after obtaining low-privileged code execution. ZDI assigned a CVSS 7.8 rating. No CVE identifier was listed in the advisory text.

  • Local privilege escalation in PAPPL IPP processing
  • Stack-based buffer overflow rated CVSS 7.8
  • Requires prior low-privileged code execution
  • Disclosure coordinated by the Zero Day Initiative
ProductsPAPPL
OrganizationsZero Day Initiative
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of PAPPL. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

This source does not provide full text. Read it at zerodayinitiative.com.