CVE-2024-47175

EUVD-2024-42297
CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
openprintinglibppd
𝑥
≤ 2.0.0
openprintinglibppd
2.1:beta1*
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openprintinglibppd
𝑥
≤ 2.1b1
ADP
Debian logo
Debian Releases
Debian Product
Codename
cups
bookworm
2.4.2-3+deb12u8
fixed
bookworm (security)
2.4.2-3+deb12u9
fixed
bullseye
vulnerable
bullseye (security)
2.3.3op2-3+deb11u10
fixed
forky
2.4.16-1
fixed
sid
2.4.16-1
fixed
trixie
2.4.10-3+deb13u2
fixed
trixie (security)
2.4.10-3+deb13u1
fixed
libppd
bookworm
2:0.10-9
fixed
bullseye
2:0.10-7.3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
bionic
Fixed 2.2.7-1ubuntu2.10+esm6
released
focal
Fixed 2.3.1-9ubuntu1.9
released
jammy
Fixed 2.4.1op1-1ubuntu4.11
released
noble
Fixed 2.4.7-1.2ubuntu7.3
released
xenial
Fixed 2.1.3-4ubuntu0.11+esm8
released
libppd
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 2:2.0.0-0ubuntu4.1
released
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cups
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
cups-client
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
cups-config
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
cups-ddk
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
cups-devel
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
cups-filters
suse enterprise desktop 15 SP6
1.25.0-150200.3.22.1
fixed
suse enterprise desktop 15 SP7
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP4
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP5
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP6
1.25.0-150200.3.22.1
fixed
suse enterprise sap 15 SP7
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP2
1.25.0-150200.3.22.1
fixed
suse enterprise server 15 SP3
1.25.0-150200.3.22.1
fixed
suse enterprise server 15 SP4
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP5
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP6
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP7
1.25.0-150200.3.28.1
fixed
cups-filters-devel
suse enterprise desktop 15 SP6
1.25.0-150200.3.22.1
fixed
suse enterprise desktop 15 SP7
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP4
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP5
1.25.0-150200.3.28.1
fixed
suse enterprise sap 15 SP6
1.25.0-150200.3.22.1
fixed
suse enterprise sap 15 SP7
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP2
1.25.0-150200.3.22.1
fixed
suse enterprise server 15 SP3
1.25.0-150200.3.22.1
fixed
suse enterprise server 15 SP4
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP5
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP6
1.25.0-150200.3.28.1
fixed
suse enterprise server 15 SP7
1.25.0-150200.3.28.1
fixed
libcups2
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
libcups2-32bit
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
libcupscgi1
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
libcupsimage2
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
libcupsmime1
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
libcupsppdc1
suse enterprise desktop 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise desktop 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise sap 15 SP7
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP2
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP3
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP4
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP5
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP6
2.2.7-150000.3.72.1
fixed
suse enterprise server 15 SP7
2.2.7-150000.3.72.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
cups
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-client
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-devel
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-filesystem
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-filters
RHEL 8
0:1.20.0-35.el8_10
fixed
RHEL 8.2 AUS
0:1.20.0-19.el8_2.2
fixed
RHEL 8.4 AUS
0:1.20.0-24.el8_4.2
fixed
RHEL 8.4 E4S
0:1.20.0-24.el8_4.2
fixed
RHEL 8.4 TUS
0:1.20.0-24.el8_4.2
fixed
RHEL 8.6 AUS
0:1.20.0-27.el8_6.3
fixed
RHEL 8.6 E4S
0:1.20.0-27.el8_6.3
fixed
RHEL 8.6 TUS
0:1.20.0-27.el8_6.3
fixed
RHEL 8.8 AUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 E4S
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 EUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 TUS
0:1.20.0-29.el8_8.3
fixed
RHEL 9
0:1.28.7-17.el9_4
fixed
cups-filters-devel
RHEL 8
0:1.20.0-35.el8_10
fixed
RHEL 8.8 AUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 E4S
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 EUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 TUS
0:1.20.0-29.el8_8.3
fixed
RHEL 9
0:1.28.7-17.el9_4
fixed
cups-filters-libs
RHEL 8
0:1.20.0-35.el8_10
fixed
RHEL 8.2 AUS
0:1.20.0-19.el8_2.2
fixed
RHEL 8.4 AUS
0:1.20.0-24.el8_4.2
fixed
RHEL 8.4 E4S
0:1.20.0-24.el8_4.2
fixed
RHEL 8.4 TUS
0:1.20.0-24.el8_4.2
fixed
RHEL 8.6 AUS
0:1.20.0-27.el8_6.3
fixed
RHEL 8.6 E4S
0:1.20.0-27.el8_6.3
fixed
RHEL 8.6 TUS
0:1.20.0-27.el8_6.3
fixed
RHEL 8.8 AUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 E4S
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 EUS
0:1.20.0-29.el8_8.3
fixed
RHEL 8.8 TUS
0:1.20.0-29.el8_8.3
fixed
RHEL 9
0:1.28.7-17.el9_4
fixed
cups-ipptool
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-libs
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-lpd
RHEL 8
1:2.2.6-62.el8_10
fixed
RHEL 9
1:2.3.3op2-31.el9_5
fixed
cups-printerapp
RHEL 9
1:2.3.3op2-31.el9_5
fixed