MGASA-2023-0284
Dashboard / Vulnerabilities / MGASA-2023-0284
MGASA-2023-0284
Summary: Updated cups packages fix security vulnerabilities
Details: The updated packages fix security vulnerabilities: It was discovered that CUPS incorrectly authenticated certain remote requests. A remote attacker could possibly use this issue to obtain recently printed documents. (CVE-2023-32360) Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. (CVE-2023-4504)
References: https://advisories.mageia.org/MGASA-2023-0284.html, https://bugs.mageia.org/show_bug.cgi?id=32281, https://www.cve.org/CVERecord?id=CVE-2023-32360, https://ubuntu.com/security/notices/USN-6361-1, https://www.cve.org/CVERecord?id=CVE-2023-4504, https://ubuntu.com/security/notices/USN-6391-1
Affected packages
Package
Name: cups
Purl: pkg:rpm/mageia/cups?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
