Command Injection in cups-filters - CVE-2024-47177

 

Command Injection in cups-filters - CVE-2024-47177

Published: September 27, 2024 / Updated: November 22, 2024


Vulnerability identifier: #VU97744
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47177
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to improper input validation in FoomaticRIPCommandLine. A remote unauthenticated attacker can use a specially crafted PPD file and execute arbitrary commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

cups-filters
Event Processing
IBM Event Endpoint Management
watsonx Assistant for IBM Cloud Pak for Data
Watson CP4D Data Stores
Dell Hybrid Client
Anolis OS
openEuler
Fedora
Chrome OS
Event Streams
cups-filters-libs
cups-filters-devel
cups-filters
cups-filters-doc
cups-filters-debuginfo
cups-filters-debugsource
cups-filters-help
cups-browsed
libppd
libcupsfilters
cups
IBM Cloud Pak for Business Automation
Optiplex 7420 All-in-One
Precision 3280
Precision 3260
OptiPlex 3000 Thin Client
Latitude 5450
OptiPlex 5400 All-In-One
Optiplex 7410 All-in-One
Optiplex 7020
Latitude 5440
Latitude 3450
Latitude 3440
Latitude 3330
OptiPlex 7010

How to mitigate CVE-2024-47177

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Event Processing - update to 1.2.2
IBM Event Endpoint Management - update to 11.3.2
Event Streams - update to 11.5.1
cups-filters-libs - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters-devel - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters-doc - update to 1.20.0-35.0.1
cups-filters - update to 1.28.9-5
cups-filters-debuginfo - update to 1.28.9-5
cups-filters-debugsource - update to 1.28.9-5
cups-filters-devel - update to 1.28.9-5
cups-filters-help - update to 1.28.9-5
cups-browsed - addressed in versions 2.0.1-3.fc39, 2.0.1-3.fc40
libppd - addressed in versions 2.1~b1-2.fc39, 2.1~b1-2.fc40
libcupsfilters - addressed in versions 2.1~b1-3.fc39, 2.1~b1-3.fc40
cups - addressed in versions 2.4.10-7.fc39, 2.4.10-7.fc40
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
Watson CP4D Data Stores - update to 5.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Chrome OS - update to 126.0.6478.254
Optiplex 7420 All-in-One - update to 2412
Precision 3280 - update to 2412
Precision 3260 - update to 2412
OptiPlex 3000 Thin Client - update to 2412
Latitude 5450 - update to 2412
OptiPlex 5400 All-In-One - update to 2412
Optiplex 7410 All-in-One - update to 2412
Optiplex 7020 - update to 2412
Latitude 5440 - update to 2412
Latitude 3450 - update to 2412
Latitude 3440 - update to 2412
Latitude 3330 - update to 2412
Dell Hybrid Client - update to 2412
OptiPlex 7010 - update to 2412

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins