← back
CVE-2023-32324highCWE-122CWE-787

OpenPrinting CUPS vulnerable to heap buffer overflow

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
In short

OpenPrinting CUPS has a memory overflow bug in its logging function that can crash the print server when debug logging is enabled. An attacker can remotely trigger this crash, disrupting printing services.

Technical detail

A heap buffer overflow in the `format_log_line` function allows remote attackers to cause denial of service when `loglevel` is set to `DEBUG` in `cupsd.conf`. The vulnerability affects CUPS versions 2.4.2 and prior; exploitation requires the debug logging configuration to be active.

Summary generated and translated by AI from the official description.
OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote attackers to cause a DoS on the affected system. Exploitation of the vulnerability can be triggered when the configuration file `cupsd.conf` sets the value of `loglevel `to `DEBUG`. No known patches or workarounds exist at time of publication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
OpenPrinting · cups