CVE-2024-47076

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 26, 2024
Updated: Nov 21, 2024
CWE ID 20

Summary

CVE-2024-47076 is a vulnerability affecting the CUPS (Common Unix Printing System) and its associated `libcupsfilters` library. The `cfGetPrinterAttributes5` function in `libcupsfilters` fails to sanitize IPP (Internet Printing Protocol) attributes obtained from IPP servers. This oversight exposes a risk, as attacker-controlled data can be introduced when these attributes are utilized to generate PPD (Printer Description) files. The consequence is unintended data being provided to the CUPS system, potentially leading to security breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share