{"id":"CVE-2023-4504","summary":"OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow","details":"Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.","modified":"2026-08-12T03:51:26.630475169Z","published":"2023-09-21T22:47:41.879Z","related":["CGA-cc9m-8c94-h5ph","GHSA-4f65-6ph5-qwh6","GHSA-pf5r-86w9-678h","SUSE-SU-2023:3706-1","SUSE-SU-2023:3707-1","SUSE-SU-2023:3707-2","SUSE-SU-2025:20090-1","openSUSE-SU-2024:13250-1"],"database_specific":{"cna_assigner":"AHA","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4504.json","unresolved_ranges":[{"extracted_events":[{"fixed":"d09348b"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Sep/33"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00041.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WHEJIYMMAIXU2EC35MGTB5LGGO2FFJE/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WVS4I7JG3LISFPKTM6ADKJXXEPEEWBQ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AMYDKIE4PSJDEMC5OWNFCDMHFGLJ57XG/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXPVADB56NMLJWG4IZ3OZBNJ2ZOLPQJ6/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2GSPQAFK2Z6L57TRXEKZDF42K2EVBH7/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4504.json"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cups/releases/tag/v2.4.7"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678h"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/libppd/security/advisories/GHSA-4f65-6ph5-qwh6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4504"},{"type":"ADVISORY","url":"https://takeonme.org/cves/CVE-2023-4504.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cups","events":[{"introduced":"0"},{"fixed":"9d614a4b3184205294c55355a1d2eb54d4532ccd"}],"database_specific":{"cpe":"cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.4.6"},{"fixed":"2.4.7"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/openprinting/libppd","events":[{"introduced":"98aca6cb5ceafa3a652ea21e3910318bdbe42e18"},{"last_affected":"98aca6cb5ceafa3a652ea21e3910318bdbe42e18"}],"database_specific":{"extracted_events":[{"introduced":"2.0-rc2"},{"last_affected":"2.0-rc2"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:openprinting:libppd:2.0:rc2:*:*:*:linux:*:*"}}],"versions":["2.0-rc2","v2.4.5","v2.4.3","v2.4.4","v2.4.2","v2.4.1","v2.4.0","v2.4rc1","v2.4b1","v2.3.3op2","v2.3.3op1","v2.3.3","v2.3.1","v2.3.0","v2.3rc1","v2.3b8","v2.3b7","v2.3b6","v2.3b5","v2.3b4","v2.3b3","v2.3b2","v2.3b1","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.2rc1","v2.2b2","v2.2b1","2.0rc2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4504.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}