PT-2024-6501 · Cups+10 · Cups+10

Evilsocket

·

Published

2024-09-26

·

Updated

2026-05-13

·

CVE-2024-47176

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups versions prior to 2.4.11-alt1 cups-browsed versions prior to 2.0.1-0ubuntu2.1 cups-filters (affected versions not specified)
Description The Common UNIX Printing System (CUPS) and related components, including cups-browsed and cups-filters, are affected by multiple vulnerabilities. These issues include remote command injection via manipulation of PPD files (libppd), improper binding of cups-browsed to all interfaces allowing unauthorized access, and a lack of sanitization of IPP attributes in cups-filters. Exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code. The cups-browsed component binds to UDP INADDR ANY:631, potentially allowing unauthorized access. The cfGetPrinterAttributes API in cups-filters does not sanitize returned IPP attributes, leading to potential vulnerabilities.
Recommendations Update to cups version 2.4.11-alt1 or later. Update to cups-browsed version 2.0.1-0ubuntu2.1 or later. Update cups-filters to the latest available version.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALSA-2024:7346
ALSA-2024:7463
ALSA-2024_7346
ALSA-2024_7463
ALT-PU-2024-14040
ALT-PU-2024-14891
BDU:2024-07643
CESA-2024_7463
CVE-2024-47176
DLA-3905-1
DSA-5778-1
ELSA-2024-7346
ELSA-2024-7463
ELSA-2024-7553
GHSA-7XFX-47QG-GRP6
GHSA-P9RH-JXMQ-GQ47
GHSA-RJ88-6MR5-RCW8
GHSA-W63J-6G73-WMG5
INFSA-2024_7346
INFSA-2024_7463
MGASA-2024-0327
OESA-2024-2246
OPENSUSE-SU-2024_3523-1
OPENSUSE-SU-2025:15563-1
RHSA-2024:7346
RHSA-2024:7461
RHSA-2024:7462
RHSA-2024:7463
RHSA-2024:7503
RHSA-2024:7504
RHSA-2024:7506
RHSA-2024:7551
RHSA-2024:7553
RHSA-2024:7623
RHSA-2024_7346
RHSA-2024_7463
RLSA-2024:7346
RLSA-2024:7463
RLSA-2024_7346
RLSA-2024_7463
ROSA-SA-2025-2556
SUSE-SU-2024:3523-1
SUSE-SU-2024:3570-1
SUSE-SU-2024:3711-1
SUSE-SU-2024_3523-1
SUSE-SU-2024_3570-1
SUSE-SU-2024_3711-1
USN-7042-1
USN-7042-2
USN-7042-3
USN-7043-1
USN-7043-2
USN-7043-3
USN-7043-4

Affected Products

Alt Linux
Almalinux
Astra Linux
Cups
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu