VDB
ALPINE-CVE-2023-4504
ALPINE-CVE-2023-4504
PUBLISHED
CVSS 7 HIGH
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
Risk Scores
CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.24 | cups | 0, 0, 0 |
| Alpine:v3.23 | cups | 1.4.2-r1, 1.4.2-r2, 1.4.3-r0 |
| Alpine:v3.18 | cups | 2.4.4-r0, 0, 1.4.1-r0 |
| Alpine:v3.20 | cups | 2.4.0-r0, 1.4.1-r0, 1.4.2-r0 |
| Alpine:v3.21 | cups | 0, 0, 1.4.1-r0 |
| Alpine:v3.17 | cups | 0, 0, 0 |
| Alpine:v3.22 | cups | 1.4.1-r0, 2.2.11-r0, 1.7.1-r0 |
| Alpine:v3.19 | cups | 0, 0, 0 |
Timeline
- Sep 21, 2023 CVE Published
- Aug 7, 2026 CVE Updated
- Aug 8, 2026 Distribution Patch