CVE-2024-47076
cups-filters - security update
8.6
HIGH
CVSS 3.1
EPSS 77.0%
描述
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.
如何修補 CVE-2024-47076
要修補 CVE-2024-47076,請將受影響套件升級到下列已修補版本。
- —升級至 1.28.7-1+deb11u3 或更新版本
- —升級至 1.28.7-1+deb11u3 或更新版本
- —升級至 1.28.17-3+deb12u1 或更新版本
- —升級至 2.0.0-3 或更新版本
CVE-2024-47076 正在被利用嗎?
可能 — EPSS 為 77.0%,屬於高被利用機率區間,建議優先修補。
受影響套件(4)
- from 0, < 1.28.7-1+deb11u3
- from 0, < 1.28.7-1+deb11u3
- from 0, < 1.28.17-3+deb12u1
- from 0, < 2.0.0-3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |