ID:10879 - Exploit for Input validation error in libppd - CVE-2024-47175

 
Main Vulnerability Database Exploits ID:10879 - Exploit for Input validation error in libppd - CVE-2024-47175

ID:10879 - Exploit for Input validation error in libppd - CVE-2024-47175

Published: November 22, 2024


Vulnerability identifier: #VU97745
Vulnerability risk: High
CVE-ID: CVE-2024-47175
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
libppd

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to ppdCreatePPDFromIPP2 does not sanitize IPP attributes when creating the PPD buffer. A remote attacker can inject attacker-controlled data in the resulting PPD.


Remediation

Install update from vendor's website.