ALAS-2023-1857

Related Vulnerabilities: CVE-2023-4504  

A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)

ALAS-2023-1857


Amazon Linux 1 Security Advisory: ALAS-2023-1857
Advisory Release Date: 2023-10-12 15:48 Pacific
Advisory Updated Date: 2023-10-24 21:38 Pacific
Severity: Medium

Issue Overview:

A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)


Affected Packages:

cups


Issue Correction:
Run yum update cups to update your system.

New Packages:
i686:
    cups-devel-1.4.2-67.25.amzn1.i686
    cups-php-1.4.2-67.25.amzn1.i686
    cups-lpd-1.4.2-67.25.amzn1.i686
    cups-1.4.2-67.25.amzn1.i686
    cups-libs-1.4.2-67.25.amzn1.i686
    cups-debuginfo-1.4.2-67.25.amzn1.i686

src:
    cups-1.4.2-67.25.amzn1.src

x86_64:
    cups-lpd-1.4.2-67.25.amzn1.x86_64
    cups-1.4.2-67.25.amzn1.x86_64
    cups-libs-1.4.2-67.25.amzn1.x86_64
    cups-php-1.4.2-67.25.amzn1.x86_64
    cups-debuginfo-1.4.2-67.25.amzn1.x86_64
    cups-devel-1.4.2-67.25.amzn1.x86_64