PT-2023-2840 · Unknown+10 · Cups-Filters+10

Winmin

·

Published

2023-05-17

·

Updated

2024-06-15

·

CVE-2023-24805

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups-filters (affected versions not specified)
Description The issue is related to the Backend Error Handler (beh) component of the cups-filters package, which does not properly sanitize special elements used in operating system commands. This can be exploited by a remote attacker to execute arbitrary commands on the print server by sending a specially crafted print job. The beh.c file contains a line that calls the system command with the operand cmdline, which includes multiple user-controlled, unsanitized values. As a result, an attacker with network access to the hosted print server can inject system commands that are executed in the context of the running server.
Recommendations To resolve the issue, users are advised to upgrade to the next release when possible. In the meantime, it is recommended to restrict access to network printers. Additionally, as a temporary workaround, consider disabling the beh component until a patch is available. Restrict access to the beh.c file to minimize the risk of exploitation. Avoid using the cmdline variable in the affected system command until the issue is resolved.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:3423
ALSA-2023:3425
ALT-PU-2023-2052
ALT-PU-2023-2053
ALT-PU-2023-2064
ALT-PU-2023-2084
ALT-PU-2023-4532
BDU:2023-02781
CESA-2023_3425
CVE-2023-24805
DLA-3430-1
DSA-5407-1
GHSA-GPXC-V2M8-FR3X
MGASA-2023-0189
OESA-2023-1315
OPENSUSE-SU-2023_2233-2
OPENSUSE-SU-2024:12939-1
RHSA-2023:3423
RHSA-2023:3424
RHSA-2023:3425
RHSA-2023:3426
RHSA-2023:3427
RHSA-2023:3428
RHSA-2023:3429
RHSA-2023_3423
RHSA-2023_3425
RLSA-2023:3423
RLSA-2023:3425
SUSE-SU-2023:2233-1
SUSE-SU-2023:2233-2
SUSE-SU-2023:2287-1
SUSE-SU-2023_2233-1
SUSE-SU-2023_2287-1
USN-6083-1
USN-6083-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Cups-Filters