Hi all,
there is the same vulnerability in CUPS and libppd projects.
The original CUPS report:
CVE-2023-4504: OpenPrinting CUPS Postscript Parsing Heap Overflow Any questions about this disclosure should be directed to cve () takeonme org.
Executive Summary Technical Details Snippet of the vulnerable code:
cups/cups/raster-interpret.c
|L///KFwAY3V1ZQ== |
Attacker Value Credit CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N
========================================================================================
Notes:
Updated Notes: Commits fixing the issue:
cups: https://github.com/OpenPrinting/cups/commit/2431caddb7e6
libppd: https://github.com/OpenPrinting/libppd/commit/262c909ac5
Have a nice day,
Zdenek Dohnal
CUPS 2.4.x release manager
-- Zdenek Dohnal Senior Software Engineer Red Hat, BRQ-TPBC