CUPS filters: Remote Code Execution — GLSA 202401-06

A vulnerability has been found in CUPS filters where remote code execution is possible via the beh filter.

Affected packages

net-print/cups-filters on all architectures
Affected versions < 1.28.17-r2
Unaffected versions >= 1.28.17-r2

Background

CUPS filters provides backends, filters, and other software that was once part of the core CUPS distribution.

Description

A vulnerability has been discovered in cups-filters. Please review the CVE identifier referenced below for details.

Impact

If you use beh to create an accessible network printer, this security vulnerability can cause remote code execution.

Workaround

There is no known workaround at this time.

Resolution

All cups-filters users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-print/cups-filters-1.28.17-r2"
 

References

Release date
January 05, 2024

Latest revision
January 05, 2024: 1

Severity
high

Exploitable
remote

Bugzilla entries