{"id":"CVE-2023-34095","summary":"cpdb-libs vulnerable to buffer overflows via scanf","details":"cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse command lines and configuration files, dropping the read string components into fixed-length buffers, but does not limit the length of the strings to be read by `fscanf()` and `scanf()` causing buffer overflows when a string is longer than 1023 characters. A patch for this issue is available at commit f181bd1f14757c2ae0f17cc76dc20421a40f30b7. As all buffers have a length of 1024 characters, the patch limits the maximum string length to be read to 1023 by replacing all occurrences of `%s` with `%1023s` in all calls of the `fscanf()` and `scanf()` functions.","aliases":["GHSA-25j7-9gfc-f46x"],"modified":"2026-04-10T04:58:56.356472Z","published":"2023-06-14T16:58:50.887Z","database_specific":{"cwe_ids":["CWE-121"],"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34095.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/06/14/7"},{"type":"WEB","url":"https://github.com/OpenPrinting/cpdb-libs/blob/85555fba64d34f53a2fce099b0488904cc48ed35/cpdb/cpdb-frontend.c#L372"},{"type":"WEB","url":"https://github.com/OpenPrinting/cpdb-libs/blob/85555fba64d34f53a2fce099b0488904cc48ed35/tools/cpdb-text-frontend.c#L362"},{"type":"WEB","url":"https://github.com/OpenPrinting/cpdb-libs/blob/85555fba64d34f53a2fce099b0488904cc48ed35/tools/cpdb-text-frontend.c#L453"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34095.json"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cpdb-libs/security/advisories/GHSA-25j7-9gfc-f46x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34095"},{"type":"FIX","url":"https://github.com/OpenPrinting/cpdb-libs/commit/f181bd1f14757c2ae0f17cc76dc20421a40f30b7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cpdb-libs","events":[{"introduced":"3d5bd324ea875bbd32898e90b496d92dca73bc69"},{"fixed":"f181bd1f14757c2ae0f17cc76dc20421a40f30b7"}]}],"versions":["2.0b1","2.0b2","2.0b3","2.0b4","2.0b4-make-install-fix","v1.0","v1.1.0","v1.1.1","v1.1.2","v1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34095.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}