ALAS2-2023-2293

Related Vulnerabilities: CVE-2023-4504  

A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)

ALAS2-2023-2293


Amazon Linux 2 Security Advisory: ALAS-2023-2293
Advisory Release Date: 2023-10-12 15:09 Pacific
Advisory Updated Date: 2023-10-19 23:40 Pacific
Severity: Medium

Issue Overview:

A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)


Affected Packages:

cups


Issue Correction:
Run yum update cups to update your system.

New Packages:
aarch64:
    cups-1.6.3-51.amzn2.0.4.aarch64
    cups-client-1.6.3-51.amzn2.0.4.aarch64
    cups-devel-1.6.3-51.amzn2.0.4.aarch64
    cups-libs-1.6.3-51.amzn2.0.4.aarch64
    cups-lpd-1.6.3-51.amzn2.0.4.aarch64
    cups-ipptool-1.6.3-51.amzn2.0.4.aarch64
    cups-debuginfo-1.6.3-51.amzn2.0.4.aarch64

i686:
    cups-1.6.3-51.amzn2.0.4.i686
    cups-client-1.6.3-51.amzn2.0.4.i686
    cups-devel-1.6.3-51.amzn2.0.4.i686
    cups-libs-1.6.3-51.amzn2.0.4.i686
    cups-lpd-1.6.3-51.amzn2.0.4.i686
    cups-ipptool-1.6.3-51.amzn2.0.4.i686
    cups-debuginfo-1.6.3-51.amzn2.0.4.i686

noarch:
    cups-filesystem-1.6.3-51.amzn2.0.4.noarch

src:
    cups-1.6.3-51.amzn2.0.4.src

x86_64:
    cups-1.6.3-51.amzn2.0.4.x86_64
    cups-client-1.6.3-51.amzn2.0.4.x86_64
    cups-devel-1.6.3-51.amzn2.0.4.x86_64
    cups-libs-1.6.3-51.amzn2.0.4.x86_64
    cups-lpd-1.6.3-51.amzn2.0.4.x86_64
    cups-ipptool-1.6.3-51.amzn2.0.4.x86_64
    cups-debuginfo-1.6.3-51.amzn2.0.4.x86_64