Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4504
HistorySep 20, 2023 - 12:00 a.m.

CVE-2023-4504

2023-09-2000:00:00
ubuntu.com
ubuntu.com
11
cve-2023-4504
buffer overflow
code execution
cups
libppd
unix
security

7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

42.4%

Due to failure in validating the length provided by an attacker-crafted PPD
PostScript document, CUPS and libppd are susceptible to a heap-based buffer
overflow and possibly code execution. This issue has been fixed in CUPS
version 2.4.7, released in September of 2023.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchcups< 2.2.7-1ubuntu2.10+esm2UNKNOWN
ubuntu20.04noarchcups< 2.3.1-9ubuntu1.6UNKNOWN
ubuntu22.04noarchcups< 2.4.1op1-1ubuntu4.7UNKNOWN
ubuntu23.04noarchcups< 2.4.2-3ubuntu2.5UNKNOWN
ubuntu23.10noarchcups< 2.4.6-0ubuntu2UNKNOWN
ubuntu24.04noarchcups< 2.4.6-0ubuntu2UNKNOWN
ubuntu16.04noarchcups< 2.1.3-4ubuntu0.11+esm4UNKNOWN
ubuntu18.04noarchlibppd< anyUNKNOWN
ubuntu20.04noarchlibppd< anyUNKNOWN
ubuntu22.04noarchlibppd< anyUNKNOWN
Rows per page:
1-10 of 141

7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

42.4%