CVE-2024-47175 is a critical vulnerability affecting CUPS libppd, specifically in Debian and OpenPrinting distributions. It stems from improper sanitization of IPP attributes in the ppdCreatePPDFromIPP2 function, which can lead to user-controlled input and, when chained with other functions like cfGetPrinterAttributes5, ultimately result in code execution via Foomatic. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring no user interaction or privileges. While not yet observed in active exploitation (KEV list), a Metasploit module exists, and community discussion is high, indicating significant interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0CPE matchmatch criteria | cpe:2.3:a:openprinting:libppd:*:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:openprinting:libppd:2.1:beta1*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025cups: libppd: remote command injection via attacker controlled data in PPD file
Sep 26, 2024