CVE-2023-4504

Severity CVSS v4.0:
Pending analysis
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
21/09/2023
Last modified:
04/11/2025

Description

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* 2.4.7 (excluding)
cpe:2.3:a:openprinting:libppd:2.0:rc2:*:*:*:linux:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools