ALAS2023-2023-361


Amazon Linux 2023 Security Advisory: ALAS-2023-361
Advisory Release Date: 2023-09-27 21:05 Pacific
Advisory Updated Date: 2023-10-03 20:50 Pacific
Severity: Medium

Issue Overview:

A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)


Affected Packages:

cups


Issue Correction:
Run dnf update cups --releasever 2023.2.20231002 to update your system.

New Packages:
aarch64:
    cups-printerapp-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-lpd-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-lpd-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-ipptool-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-libs-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-debugsource-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-client-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-devel-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-libs-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-printerapp-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-client-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-ipptool-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
    cups-2.3.3op2-18.amzn2023.0.7.aarch64

noarch:
    cups-filesystem-2.3.3op2-18.amzn2023.0.7.noarch

src:
    cups-2.3.3op2-18.amzn2023.0.7.src

x86_64:
    cups-lpd-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-devel-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-debugsource-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-lpd-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-client-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-printerapp-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-client-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-ipptool-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-libs-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-libs-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-printerapp-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-ipptool-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
    cups-2.3.3op2-18.amzn2023.0.7.x86_64