Description
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3594-1 | cups security update |
EUVD |
EUVD-2023-54359 | Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023. |
Ubuntu USN |
USN-6391-1 | CUPS vulnerability |
Ubuntu USN |
USN-6391-2 | CUPS vulnerability |
Ubuntu USN |
USN-6392-1 | libppd vulnerability |
References
History
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 24 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023. | Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023. |
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2025-11-04T16:10:38.138Z
Reserved: 2023-08-23T21:14:04.183Z
Link: CVE-2023-4504
Updated: 2025-11-04T16:10:38.138Z
Status : Modified
Published: 2023-09-21T23:15:12.293
Modified: 2025-11-04T17:15:41.697
Link: CVE-2023-4504
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN