CVE-2023-24805
cups-filters - security update
描述
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` which calls the `system` command with the operand `cmdline`. `cmdline` contains multiple user controlled, unsanitized values. As a result an attacker with network access to the hosted print server can exploit this vulnerability to inject system commands which are executed in the context of the running server. This issue has been addressed in commit `8f2740357` and is expected to be bundled in the next release. Users are advised to upgrade when possible and to restrict access to network printers in the meantime.
如何修補 CVE-2023-24805
要修補 CVE-2023-24805,請將受影響套件升級到下列已修補版本。
- —升級至 1.28.7-1+deb11u2 或更新版本
- —升級至 1.21.6-5+deb10u1 或更新版本
- —升級至 1.28.7-1+deb11u2 或更新版本
CVE-2023-24805 正在被利用嗎?
低 — EPSS 為 3.7%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 1.28.7-1+deb11u2
- from 0, < 1.21.6-5+deb10u1
- from 0, < 1.28.7-1+deb11u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |