Bug 2314256 (CVE-2024-47175)
| Summary: | CVE-2024-47175 cups: libppd: remote command injection via attacker controlled data in PPD file | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | asdas, bmontgom, dpaolell, eparis, gotiwari, jburrell, jdelft, jhorak, jupierce, jwest, kyoshida, lgarciaa, mbiarnes, mvyas, nstielau, security-response-team, sidsharm, sponnaga, talessio, tpopela, vlaad, zdohnal, zmiele |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A security vulnerability was found in OpenPrinting CUPS.
The function ppdCreatePPDFromIPP2 in the libppd library is responsible for generating a PostScript Printer Description (PPD) file based on attributes retrieved from an Internet Printing Protocol (IPP) response. Essentially, it takes printer information, usually obtained via IPP, and creates a corresponding PPD file that describes the printer's capabilities (such as supported media sizes, resolutions, color modes, etc.).
PPD files are used by printing systems like CUPS (Common Unix Printing System) to communicate with and configure printers. They provide a standardized format that allows different printers to work with the printing system in a consistent way.
The ppdCreatePPDFromIPP2 function in libppd doesn't properly check or clean IPP attributes before writing them to a temporary PPD file. This means that a remote attacker, who has control of or has hijacked an exposed printer (through UPD or mDNS), could send a harmful IPP attribute and potentially insert malicious commands into the PPD file.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2315001, 2315002, 2315004 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2024-09-23 17:10:28 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:7346 https://access.redhat.com/errata/RHSA-2024:7346 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:7461 https://access.redhat.com/errata/RHSA-2024:7461 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:7462 https://access.redhat.com/errata/RHSA-2024:7462 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:7463 https://access.redhat.com/errata/RHSA-2024:7463 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2024:7506 https://access.redhat.com/errata/RHSA-2024:7506 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2024:7504 https://access.redhat.com/errata/RHSA-2024:7504 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:7503 https://access.redhat.com/errata/RHSA-2024:7503 This issue has been addressed in the following products: Red Hat Enterprise Linux 7.7 Advanced Update Support Via RHSA-2024:7551 https://access.redhat.com/errata/RHSA-2024:7551 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2024:7553 https://access.redhat.com/errata/RHSA-2024:7553 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:7623 https://access.redhat.com/errata/RHSA-2024:7623 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9470 https://access.redhat.com/errata/RHSA-2024:9470 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:0083 https://access.redhat.com/errata/RHSA-2025:0083 |