ALPINE-CVE-2023-4504

Source
https://security.alpinelinux.org/vuln/CVE-2023-4504
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-4504.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2023-4504
Upstream
Published
2023-09-21T23:15:12.293Z
Modified
2025-11-19T06:20:42.525441Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

References

Affected packages

Alpine:v3.17

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3

Alpine:v3.18

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3
2.4.2-r4
2.4.2-r5
2.4.2-r6
2.4.2-r7
2.4.3-r0
2.4.3-r1
2.4.4-r0
2.4.5-r0
2.4.6-r0

Alpine:v3.19

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3
2.4.2-r4
2.4.2-r5
2.4.2-r6
2.4.2-r7
2.4.3-r0
2.4.3-r1
2.4.4-r0
2.4.5-r0
2.4.6-r0

Alpine:v3.20

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3
2.4.2-r4
2.4.2-r5
2.4.2-r6
2.4.2-r7
2.4.3-r0
2.4.3-r1
2.4.4-r0
2.4.5-r0
2.4.6-r0

Alpine:v3.21

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3
2.4.2-r4
2.4.2-r5
2.4.2-r6
2.4.2-r7
2.4.3-r0
2.4.3-r1
2.4.4-r0
2.4.5-r0
2.4.6-r0

Alpine:v3.22

cups

Package

Name
cups
Purl
pkg:apk/alpine/cups?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-r0

Affected versions

1.*

1.4.1-r0
1.4.2-r0
1.4.2-r1
1.4.2-r2
1.4.3-r0
1.4.3-r1
1.4.3-r2
1.4.3-r3
1.4.4-r0
1.4.4-r1
1.4.5-r0
1.4.6-r0
1.4.7-r0
1.4.8-r0
1.5.0-r0
1.5.0-r1
1.5.0-r2
1.5.2-r0
1.5.2-r1
1.5.2-r2
1.5.2-r3
1.5.3-r0
1.5.4-r0
1.5.4-r1
1.6.1-r0
1.6.1-r1
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.4-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.2-r0
1.7.3-r0
1.7.3-r1
1.7.4-r0
1.7.5-r0

2.*

2.0.0-r0
2.0.1-r0
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.3-r0
2.0.4-r0
2.1.0-r0
2.1.1-r0
2.1.2-r0
2.1.3-r0
2.1.3-r1
2.1.4-r0
2.2.1-r0
2.2.1-r1
2.2.2-r0
2.2.2-r1
2.2.2-r2
2.2.3-r0
2.2.3-r1
2.2.4-r0
2.2.5-r0
2.2.5-r1
2.2.6-r0
2.2.9-r0
2.2.10-r0
2.2.11-r0
2.2.12-r0
2.2.12-r1
2.2.12-r2
2.3.3-r0
2.3.3-r1
2.3.3-r2
2.3.3-r3
2.3.3-r4
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.2-r1
2.4.2-r2
2.4.2-r3
2.4.2-r4
2.4.2-r5
2.4.2-r6
2.4.2-r7
2.4.3-r0
2.4.3-r1
2.4.4-r0
2.4.5-r0
2.4.6-r0