All errata/sisyphus_e2k/ALT-PU-2023-6037-1
ALT-PU-2023-6037-1

Package update libppd in branch sisyphus_e2k

Version2.0.0-alt1
Task#0
Published2023-09-29
Max severityHIGH
Severity:

Closed issues (1)

CVE-2023-4504
HIGH7.0

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Published: 2023-09-21Modified: 2025-11-04
CVSS 3.xHIGH 7.0
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References