CVE-2023-24805
Publication date 17 May 2023
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` which calls the `system` command with the operand `cmdline`. `cmdline` contains multiple user controlled, unsanitized values. As a result an attacker with network access to the hosted print server can exploit this vulnerability to inject system commands which are executed in the context of the running server. This issue has been addressed in commit `8f2740357` and is expected to be bundled in the next release. Users are advised to upgrade when possible and to restrict access to network printers in the meantime.
Status
Package | Ubuntu Release | Status |
---|---|---|
cups-filters | ||
22.04 LTS jammy |
Fixed 1.28.15-0ubuntu1.2
|
|
20.04 LTS focal |
Fixed 1.27.4-1ubuntu0.2
|
|
18.04 LTS bionic |
Fixed 1.20.2-0ubuntu3.3
|
|
16.04 LTS xenial |
Fixed 1.8.3-2ubuntu3.5+esm1
|
|
14.04 LTS trusty | Ignored end of standard support |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score | 8.8 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6083-1
- cups-filters vulnerability
- 17 May 2023
- USN-6083-2
- cups-filters vulnerability
- 19 June 2023