CVE-2023-32324: OpenPrinting CUPS vulnerable to heap buffer overflow
A buffer overflow vulnerability in the function |formatlogline| could allow remote attackers to cause a denial-of-service(DoS) on the affected system (not verified for possible arbitrary code execution). Exploitation of the vulnerability can be triggered when the configuration file |cupsd.conf| sets the value of |loglevel |to |DEBUG|.
Other sources
OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function formatlogline could allow remote attackers to cause a DoS on the affected system. Exploitation of the vulnerability can be triggered when the configuration file cupsd.conf sets the value of loglevel to DEBUG. No known patches or workarounds exist at time of publication.
— Ubuntu
OpenPrinting CUPS is vulnerable to a denial of service, caused by improper bounds checking in cupsd when parsing raw files. By persuading a victim to open a specially crafted raw file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-32324?
CVE-2023-32324 is a heap buffer overflow vulnerability in cupsd, the OpenPrinting CUPS daemon, that could allow a remote attacker to launch a denial of service (DoS) attack.
Which versions of CUPS are affected by CVE-2023-32324?
Versions 2.4.2 and prior of CUPS are affected by CVE-2023-32324.
How severe is CVE-2023-32324?
CVE-2023-32324 has a high severity rating with a CVSS score of 5.5.
How do I fix CVE-2023-32324 on Ubuntu?
For Ubuntu, the specific versions that fix CVE-2023-32324 are: 2.2.7-1ubuntu2.10, 2.3.1-9ubuntu1.3, 2.4.1, 2.4.2-1ubuntu2.1, 2.4.2-3ubuntu2.1, and 2.1.3-4ubuntu0.11+.
How do I fix CVE-2023-32324 on Debian?
For Debian, the specific versions that fix CVE-2023-32324 are: 2.2.10-6+deb10u9, 2.3.3op2-3+deb11u6, 2.4.2-3+deb12u4, and 2.4.7-1.