CVE-2024-47175

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 26, 2024
Updated: Nov 21, 2024
CWE ID 20

Summary

CVE-2024-47175 represents a vulnerability in the open-source printing system CUPS, specifically within the `libppd` library. The function `ppdCreatePPDFromIPP2` in `libppd` fails to sanitize IPP attributes when building the PPD buffer. This flaw, when combined with other functions like `cfGetPrinterAttributes5`, allows user-controlled input, potentially leading to code execution via Foomatic. This vulnerability could serve as a step in a larger exploit chain towards remote code execution, as outlined in CVE-2024-47176.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share