rpm package
opensuse/cups-filters&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/cups-filters&distro=openSUSE%20Leap%2016.0
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-64611 | Hig | 7.5 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Jul 23, 2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadca | |
| CVE-2026-64612 | Hig | 7.5 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Jul 20, 2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit | |
| CVE-2024-47850 | Hig | 7.5 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Oct 4, 2024 | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be use | |
| CVE-2024-47176 | Med | 5.3 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any | |
| CVE-2024-47175 | Hig | 8.6 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPr | |
| CVE-2024-47076 | Hig | 8.6 | < 1.28.17-bp160.2.1 | 1.28.17-bp160.2.1 | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` fu |
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadca
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be use
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPr
- affected < 1.28.17-bp160.2.1fixed 1.28.17-bp160.2.1
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` fu