CVE-2023-32324

medium
Published 2023-11-07 · Modified 2023-11-14
CVSS v3
VIR risk
5.5

Description

Moderate: cups security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description cups: heap buffer overflow may lead to DoS CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z Red Hat Enterprise Linux 8.6 Extended Update…

Description

cups: heap buffer overflow may lead to DoS

CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z
Red Hat Enterprise Linux 8cups-1:2.2.6-54.el8_9RHSA-2023:71652023-11-14T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportcups-1:2.2.6-45.el8_6.4RHSA-2024:11012024-03-05T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportcups-1:2.2.6-51.el8_8.3RHSA-2024:14092024-03-19T00:00:00Z
Red Hat Enterprise Linux 9cups-1:2.3.3op2-21.el9RHSA-2023:65962023-11-07T00:00:00Z
Red Hat Enterprise Linux 9cups-1:2.3.3op2-21.el9RHSA-2023:65962023-11-07T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6cupsOut of support scope
Red Hat Enterprise Linux 7cupsWill not fix

Apply commands

bash fix
Apply RHSA-2023:7165 for Red Hat Enterprise Linux 8
yum update -y cups
# or:
dnf upgrade -y cups

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
debian debianbookwormfixed2.4.2-3+deb12u1
debian debianbullseyefixed2.3.3op2-3+deb11u3
debian debianforkyfixed2.4.2-4
debian debiansidfixed2.4.2-4
debian debiantrixiefixed2.4.2-4
suse slesaffected
almalinux almalinux9fixedcups-devel-2.3.3op2-21.el9.aarch64.rpm

References

💬 Discuss CVE-2023-32324 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.