UBUNTU-CVE-2024-47175

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2024-47175
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-47175.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-47175
Related
Published
2024-10-06T19:00:00Z
Modified
2024-10-04T11:32:06Z
Summary
[none]
Details

CUPS is a standards-based, open-source printing system, and libppd can be used for legacy PPD file support. The libppd function ppdCreatePPDFromIPP2 does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as cfGetPrinterAttributes5, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176.

References

Affected packages

Ubuntu:Pro:16.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.1.0-4ubuntu3
2.1.0-5
2.1.0-6
2.1.0-6ubuntu1
2.1.0-7
2.1.2-1
2.1.2-2
2.1.3-1
2.1.3-1build1
2.1.3-3
2.1.3-4
2.1.3-4ubuntu0.2
2.1.3-4ubuntu0.3
2.1.3-4ubuntu0.4
2.1.3-4ubuntu0.5
2.1.3-4ubuntu0.6
2.1.3-4ubuntu0.7
2.1.3-4ubuntu0.8
2.1.3-4ubuntu0.9
2.1.3-4ubuntu0.10
2.1.3-4ubuntu0.11
2.1.3-4ubuntu0.11+esm1
2.1.3-4ubuntu0.11+esm2
2.1.3-4ubuntu0.11+esm3
2.1.3-4ubuntu0.11+esm4
2.1.3-4ubuntu0.11+esm5
2.1.3-4ubuntu0.11+esm6
2.1.3-4ubuntu0.11+esm7

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.7-1ubuntu2.10+esm6

Affected versions

2.*

2.2.4-7ubuntu2
2.2.5-2
2.2.6-2
2.2.6-3
2.2.6-4
2.2.6-5
2.2.7-1ubuntu1
2.2.7-1ubuntu2
2.2.7-1ubuntu2.1
2.2.7-1ubuntu2.2
2.2.7-1ubuntu2.3
2.2.7-1ubuntu2.4
2.2.7-1ubuntu2.5
2.2.7-1ubuntu2.6
2.2.7-1ubuntu2.7
2.2.7-1ubuntu2.8
2.2.7-1ubuntu2.9
2.2.7-1ubuntu2.10
2.2.7-1ubuntu2.10+esm1
2.2.7-1ubuntu2.10+esm2
2.2.7-1ubuntu2.10+esm3
2.2.7-1ubuntu2.10+esm4
2.2.7-1ubuntu2.10+esm5

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-bsd-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-client-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-core-drivers-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-daemon-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-ipp-utils-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-ppdc-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcups2"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcups2-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupscgi1"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupscgi1-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsimage2"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsimage2-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsimage2-dev"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsmime1"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsmime1-dbgsym"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsppdc1"
        },
        {
            "binary_version": "2.2.7-1ubuntu2.10+esm6",
            "binary_name": "libcupsppdc1-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.1-9ubuntu1.9

Affected versions

2.*

2.2.12-2ubuntu1
2.3.0-6
2.3.0-7
2.3.0-7ubuntu1
2.3.1-1ubuntu1
2.3.1-2
2.3.1-4
2.3.1-7
2.3.1-9ubuntu1
2.3.1-9ubuntu1.1
2.3.1-9ubuntu1.2
2.3.1-9ubuntu1.3
2.3.1-9ubuntu1.4
2.3.1-9ubuntu1.5
2.3.1-9ubuntu1.6
2.3.1-9ubuntu1.7
2.3.1-9ubuntu1.8

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-bsd-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-client-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-core-drivers-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-daemon-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-ipp-utils-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-ppdc-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcups2"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcups2-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcupsimage2"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcupsimage2-dbgsym"
        },
        {
            "binary_version": "2.3.1-9ubuntu1.9",
            "binary_name": "libcupsimage2-dev"
        }
    ]
}

Ubuntu:22.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.1op1-1ubuntu4.11

Affected versions

2.*

2.3.3op2-7ubuntu2
2.4.1op1-1ubuntu1
2.4.1op1-1ubuntu2
2.4.1op1-1ubuntu3
2.4.1op1-1ubuntu4
2.4.1op1-1ubuntu4.1
2.4.1op1-1ubuntu4.2
2.4.1op1-1ubuntu4.4
2.4.1op1-1ubuntu4.6
2.4.1op1-1ubuntu4.7
2.4.1op1-1ubuntu4.8
2.4.1op1-1ubuntu4.9
2.4.1op1-1ubuntu4.10

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-bsd-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-client-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-core-drivers-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-daemon-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-ipp-utils-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-ppdc-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcups2"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcups2-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcupsimage2"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcupsimage2-dbgsym"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.11",
            "binary_name": "libcupsimage2-dev"
        }
    ]
}

Ubuntu:24.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-1.2ubuntu7.3

Affected versions

2.*

2.4.6-0ubuntu3
2.4.7-1.2ubuntu2
2.4.7-1.2ubuntu3
2.4.7-1.2ubuntu7
2.4.7-1.2ubuntu7.1
2.4.7-1.2ubuntu7.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-bsd-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-client-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-core-drivers-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-daemon-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-ipp-utils-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-ppdc-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcups2t64"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcups2t64-dbgsym"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcupsimage2-dev"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcupsimage2t64"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.3",
            "binary_name": "libcupsimage2t64-dbgsym"
        }
    ]
}

Ubuntu:24.04:LTS / libppd

Package

Name
libppd
Purl
pkg:deb/ubuntu/libppd?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:2.0.0-0ubuntu4.1

Affected versions

2:2.*

2:2.0.0-0ubuntu1
2:2.0.0-0ubuntu3
2:2.0.0-0ubuntu4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd-dev"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd-tests"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd-tests-dbgsym"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd-utils"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd-utils-dbgsym"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd2"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd2-common"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "libppd2-dbgsym"
        },
        {
            "binary_version": "2:2.0.0-0ubuntu4.1",
            "binary_name": "ppdc"
        }
    ]
}