Amazon Linux 2023 Security Advisory: ALAS-2023-361
Advisory Release Date: 2023-09-27 21:05 Pacific
Advisory Updated Date: 2023-10-03 20:50 Pacific
A vulnerability was found in OpenPrinting CUPS. The security flaw occurs due to failure in validating the length provided by an attacker-crafted CUPS document, possibly leading to a heap-based buffer overflow and code execution. (CVE-2023-4504)
Affected Packages:
cups
Issue Correction:
Run dnf update cups --releasever 2023.2.20231002 to update your system.
aarch64:
cups-printerapp-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-lpd-2.3.3op2-18.amzn2023.0.7.aarch64
cups-lpd-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-ipptool-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-libs-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-debugsource-2.3.3op2-18.amzn2023.0.7.aarch64
cups-client-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-devel-2.3.3op2-18.amzn2023.0.7.aarch64
cups-libs-2.3.3op2-18.amzn2023.0.7.aarch64
cups-printerapp-2.3.3op2-18.amzn2023.0.7.aarch64
cups-client-2.3.3op2-18.amzn2023.0.7.aarch64
cups-ipptool-2.3.3op2-18.amzn2023.0.7.aarch64
cups-debuginfo-2.3.3op2-18.amzn2023.0.7.aarch64
cups-2.3.3op2-18.amzn2023.0.7.aarch64
noarch:
cups-filesystem-2.3.3op2-18.amzn2023.0.7.noarch
src:
cups-2.3.3op2-18.amzn2023.0.7.src
x86_64:
cups-lpd-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-devel-2.3.3op2-18.amzn2023.0.7.x86_64
cups-debugsource-2.3.3op2-18.amzn2023.0.7.x86_64
cups-lpd-2.3.3op2-18.amzn2023.0.7.x86_64
cups-client-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-printerapp-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-client-2.3.3op2-18.amzn2023.0.7.x86_64
cups-ipptool-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-libs-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-libs-2.3.3op2-18.amzn2023.0.7.x86_64
cups-printerapp-2.3.3op2-18.amzn2023.0.7.x86_64
cups-ipptool-2.3.3op2-18.amzn2023.0.7.x86_64
cups-debuginfo-2.3.3op2-18.amzn2023.0.7.x86_64
cups-2.3.3op2-18.amzn2023.0.7.x86_64