CVE-2023-32324

medium
Published 2023-11-07 Β· Modified 2023-11-14
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2023:7165: cups security and bug fix update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description cups: heap buffer overflow may lead to DoS CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z Red Hat Enterprise Linux 8.6 Extended Update…

Description

cups: heap buffer overflow may lead to DoS

CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z
Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportcups-1:2.2.6-45.el8_6.4RHSA-2024:11012024-03-05T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportcups-1:2.2.6-51.el8_8.3RHSA-2024:14092024-03-19T00:00:00Z
Red Hat Enterprise Linux 9cups-1:2.3.3op2-21.el9RHSA-2023:65962023-11-07T00:00:00Z
Red Hat Enterprise Linux 9cups-1:2.3.3op2-21.el9RHSA-2023:65962023-11-07T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6cupsOut of support scope
Red Hat Enterprise Linux 7cupsWill not fix

Apply commands

bash fix
Apply RHSA-2023:7165 for Red Hat Enterprise Linux 8
yum update -y cups
# or:
dnf upgrade -y cups

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed cups-devel-2.3.3op2-21.el9.aarch64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.2-4
sid Fixed 2.4.2-4
forky Fixed 2.4.2-4
bullseye Fixed 2.3.3op2-3+deb11u3
bookworm Fixed 2.4.2-3+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.