PT-2023-2840 · Unknown+10 · Cups-Filters+10
Winmin
·
Published
2023-05-17
·
Updated
2024-06-15
·
CVE-2023-24805
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
cups-filters (affected versions not specified)
Description
The issue is related to the Backend Error Handler (beh) component of the cups-filters package, which does not properly sanitize special elements used in operating system commands. This can be exploited by a remote attacker to execute arbitrary commands on the print server by sending a specially crafted print job. The
beh.c file contains a line that calls the system command with the operand cmdline, which includes multiple user-controlled, unsanitized values. As a result, an attacker with network access to the hosted print server can inject system commands that are executed in the context of the running server.Recommendations
To resolve the issue, users are advised to upgrade to the next release when possible. In the meantime, it is recommended to restrict access to network printers. Additionally, as a temporary workaround, consider disabling the
beh component until a patch is available. Restrict access to the beh.c file to minimize the risk of exploitation. Avoid using the cmdline variable in the affected system command until the issue is resolved.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Cups-Filters