- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3904-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
September 29, 2024                            https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : cups
Version        : 2.3.3op2-3+deb11u9
CVE ID         : CVE-2024-47175


Simone Margaritelli reported that cups, the Common UNIX Printing System,
does not properly sanitize IPP attributes when creating PPD files, which
may result in the execution of arbitrary code.


For Debian 11 bullseye, this problem has been fixed in version
2.3.3op2-3+deb11u9.

We recommend that you upgrade your cups packages.

For the detailed security status of cups please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/cups

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3904-1: cups Security Advisory Updates

September 29, 2024
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arb...

Summary

Simone Margaritelli reported that cups, the Common UNIX Printing System,
does not properly sanitize IPP attributes when creating PPD files, which
may result in the execution of arbitrary code.


For Debian 11 bullseye, this problem has been fixed in version
2.3.3op2-3+deb11u9.

We recommend that you upgrade your cups packages.

For the detailed security status of cups please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/cups

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : cups
Version : 2.3.3op2-3+deb11u9
CVE ID : CVE-2024-47175

Related News