CUPS Vulnerability Allows Remote Command Execution

CVE-2024-47177

9.1CRITICAL

Key Information

Vendor
Openprinting
Status
Cups-filters
Vendor
CVE Published:
26 September 2024

Badges

šŸ‘¾ Exploit ExistsšŸ“° News Worthy

Summary

CUPS is a standards-based, open-source printing system, and cups-filters provides backends, filters, and other software for CUPS 2.x to use on non-Mac OS systems. Any value passed to FoomaticRIPCommandLine via a PPD file will be executed as a user controlled command. When combined with other logic bugs as described in CVE_2024-47176, this can lead to remote command execution.

Affected Version(s)

cups-filters = <= 2.0.1

News Articles

Unix CUPS Unauthenticated RCE Zero-Day Vulnerabilities: All you need to know - KBI.Media

On September 23rd, Twitter userĀ Simone Margaritelli (@evilsocket) announcedĀ that he has discovered and privately disclosed a CVSS 9.9 GNU/Linux unauthenticated RCE, which affects almost all Linux distributions, and that the public disclosure will happen on September 30th, Due to a suspected leak in ...

1 month ago

Unix CUPS Unauthenticated RCE Zero-Day Vulnerabilities (CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177): All you need to know

On September 23rd, Twitter user Simone Margaritelli (@evilsocket) announced that he has discovered and privately disclosed a CVSS 9.9 GNU/Linux unauthenticated RCE, which affects almost all Linux distributions, and that the public disclosure will happen on September 30th, Due to a suspected leak in ...

2 months ago

Refferences

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • šŸ‘¾

    Exploit known to exist

  • First article discovered by JFrog

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database2 News Article(s)
.