CVE-2023-4504

Source
https://cve.org/CVERecord?id=CVE-2023-4504
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4504.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4504
Downstream
Related
Published
2023-09-21T22:47:41.879Z
Modified
2026-07-15T01:49:01.801847471Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
Details

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "d09348b"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-122"
    ],
    "cna_assigner": "AHA",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4504.json"
}
References

Affected packages

Git / github.com/openprinting/cups

Affected ranges

Type
GIT
Repo
https://github.com/openprinting/cups
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.4.6"
        },
        {
            "fixed": "2.4.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/openprinting/libppd
Events
Database specific
{
    "cpe": "cpe:2.3:a:openprinting:libppd:2.0:rc2:*:*:*:linux:*:*",
    "extracted_events": [
        {
            "introduced": "2.0-rc2"
        },
        {
            "last_affected": "2.0-rc2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.0-rc2
2.0rc2
v2.*
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2b1
v2.2b2
v2.2rc1
v2.3.0
v2.3.1
v2.3.3
v2.3.3op1
v2.3.3op2
v2.3b1
v2.3b2
v2.3b3
v2.3b4
v2.3b5
v2.3b6
v2.3b7
v2.3b8
v2.3rc1
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4b1
v2.4rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4504.json"