CVE-2024-47076

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openprinting:libcupsfilters:*:*:*:*:*:*:*:*
cpe:2.3:a:openprinting:libcupsfilters:2.1:beta1:*:*:*:*:*:*

History

03 Nov 2025, 23:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/09/msg00048.html -
  • () https://security.netapp.com/advisory/ntap-20241011-0001/ -

Information

Published : 2024-09-26 22:15

Updated : 2025-11-03 23:16


NVD link : CVE-2024-47076

Mitre link : CVE-2024-47076

CVE.ORG link : CVE-2024-47076


JSON object : View

Products Affected

openprinting

  • libcupsfilters
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo