Command injection in cups-filters
CVE-2023-24805
8.8HIGH
What is CVE-2023-24805?
The cups-filters package, utilized for managing the CUPS printing service on non-macOS systems, contains a vulnerability that could lead to remote code execution. This issue arises from the improper handling of unsanitized input in the Backend Error Handler (beh). When an attacker gains network access to a vulnerable print server, they can exploit this vulnerability to inject arbitrary system commands. This unauthorized execution occurs within the context of the server, potentially allowing the attacker to manipulate the system. Users are advised to promptly update to the patched version, which includes critical security fixes, and to limit access to network printers as a precautionary measure.
Affected Version(s)
cups-filters <= 2.0rc1
