Logo
vulnerabilityCVE-2024-47076
Name
CVE-2024-47076
Source
NVD ( link)Debian ( link)
Description
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.
Published Date
Updated Date
Workaround
-

Analysis#


Vulnerability Ratings#


8.6
CVSSv31
8.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.28.17
Exploitable
buildroot
master
1.28.17
Exploitable
yocto
kirkstone
1.28.11
Exploitable
yocto
master
2.0.1
Not Affected
yocto
master
2.1.1
Not Affected

Resolved with patches#


libcupsfilters (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2024-47076
Zdenek Dohnal <zdohnal@redhat.com>
CVE-2024-47076