CVE-2024-47076
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Sep 26, 2024
Updated: Nov 21, 2024
CWE ID 20
Summary
CVE-2024-47076 is a vulnerability affecting the CUPS (Common Unix Printing System) and its associated `libcupsfilters` library. The `cfGetPrinterAttributes5` function in `libcupsfilters` fails to sanitize IPP (Internet Printing Protocol) attributes obtained from IPP servers. This oversight exposes a risk, as attacker-controlled data can be introduced when these attributes are utilized to generate PPD (Printer Description) files. The consequence is unintended data being provided to the CUPS system, potentially leading to security breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.