← Back

CVE-2024-47076

nvd nist
Published: Sep 26, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

Affected (2)

1 product
Libcupsfilters
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Openprinting
Up to 2.0.0
Version 2.1 beta1

References (9)

Source: security-advisories@github.com
ExploitVendor Advisory
Source: security-advisories@github.com
Not Applicable
Source: security-advisories@github.com
Product
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.