CVE-2023-4504

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
openprintingcups
𝑥
< 2.4.7
openprintinglibppd
2.0:rc2
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bookworm
2.4.2-3+deb12u8
fixed
bookworm (security)
2.4.2-3+deb12u8
fixed
bullseye
2.3.3op2-3+deb11u8
fixed
bullseye (security)
2.3.3op2-3+deb11u9
fixed
sid
2.4.10-2
fixed
trixie
2.4.10-2
fixed
libppd
bookworm
2:0.10-9
fixed
bullseye
2:0.10-7.3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
bionic
Fixed 2.2.7-1ubuntu2.10+esm2
released
focal
Fixed 2.3.1-9ubuntu1.6
released
jammy
Fixed 2.4.1op1-1ubuntu4.7
released
lunar
Fixed 2.4.2-3ubuntu2.5
released
mantic
Fixed 2.4.6-0ubuntu2
released
noble
Fixed 2.4.6-0ubuntu2
released
oracular
Fixed 2.4.6-0ubuntu2
released
trusty
ignored
xenial
Fixed 2.1.3-4ubuntu0.11+esm4
released
libppd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
Fixed 2:2.0~rc1-0ubuntu1.2
released
mantic
Fixed 2:2.0~rc1-0ubuntu4
released
noble
Fixed 2:2.0~rc1-0ubuntu4
released
oracular
Fixed 2:2.0~rc1-0ubuntu4
released
trusty
ignored
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cups
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 12 SP5
1.7.5-20.46.1
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 12 SP2
1.7.5-20.46.1
fixed
suse enterprise server 12 SP3
1.7.5-20.46.1
fixed
suse enterprise server 12 SP4
1.7.5-20.46.1
fixed
suse enterprise server 12 SP5
1.7.5-20.46.1
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
cups-client
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 12 SP5
1.7.5-20.46.1
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 12 SP2
1.7.5-20.46.1
fixed
suse enterprise server 12 SP3
1.7.5-20.46.1
fixed
suse enterprise server 12 SP4
1.7.5-20.46.1
fixed
suse enterprise server 12 SP5
1.7.5-20.46.1
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
cups-config
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
cups-ddk
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
cups-devel
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
cups-libs
suse enterprise sap 12 SP5
1.7.5-20.46.1
fixed
suse enterprise server 12 SP2
1.7.5-20.46.1
fixed
suse enterprise server 12 SP3
1.7.5-20.46.1
fixed
suse enterprise server 12 SP4
1.7.5-20.46.1
fixed
suse enterprise server 12 SP5
1.7.5-20.46.1
fixed
cups-libs-32bit
suse enterprise sap 12 SP5
1.7.5-20.46.1
fixed
suse enterprise server 12 SP2
1.7.5-20.46.1
fixed
suse enterprise server 12 SP3
1.7.5-20.46.1
fixed
suse enterprise server 12 SP4
1.7.5-20.46.1
fixed
suse enterprise server 12 SP5
1.7.5-20.46.1
fixed
libcups2
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
libcups2-32bit
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
libcupscgi1
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
libcupsimage2
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
libcupsmime1
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
libcupsppdc1
suse enterprise desktop 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP1
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.51.2
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.51.2
fixed
References