Red Hat Security Advisory: cups-filters security update
Multiple security vulnerabilities have been identified in the cups-filters package used in Red Hat Enterprise Linux versions 7 and 8.6. Notably, the libcupsfilters cfGetPrinterAttributes API does not sanitize returned IPP attributes (CVE-2024-47076), which could lead to security issues. Additional vulnerabilities include remote command injection via attacker-controlled data in PPD files and a DDoS amplification attack vector in cups-browsed. Red Hat has released security updates addressing these issues for affected versions.
AI Analysis
Technical Summary
The cups-filters package, which includes back ends, filters, and other software previously part of CUPS, contains several security flaws. CVE-2024-47076 concerns the libcupsfilters `cfGetPrinterAttributes` API failing to sanitize IPP attributes, potentially allowing malicious input to be processed unsafely. Other related vulnerabilities include cups-browsed binding to UDP INADDR_ANY:631 and accepting packets from any source (CVE-2024-47176), remote command injection via PPD files (CVE-2024-47175), and a DDoS amplification attack vector (CVE-2024-47850). Red Hat has issued security advisories and patches for these issues in their Enterprise Linux 7 Extended Lifecycle Support and 8.2 Advanced Update Support releases.
Potential Impact
The vulnerabilities could allow attackers to exploit unsanitized input in IPP attributes, potentially leading to unauthorized command execution or other malicious actions. The remote command injection vulnerability via PPD files could enable attackers to execute arbitrary commands. The cups-browsed UDP binding issue may allow attackers to send malicious packets, potentially leading to denial of service or amplification attacks. These issues collectively pose a significant security risk to affected systems running vulnerable versions of cups-filters.
Mitigation Recommendations
Red Hat has released official security updates for the cups-filters package addressing these vulnerabilities. Users should apply the updates provided for Red Hat Enterprise Linux 7 Extended Lifecycle Support and 8.2 Advanced Update Support as detailed in Red Hat advisories RHSA-2024:7553 and RHSA-2024:7461. Refer to https://access.redhat.com/articles/11258 for update instructions. Applying these patches mitigates the vulnerabilities. No additional vendor-recommended mitigations are specified.
Red Hat Security Advisory: cups-filters security update
Description
Multiple security vulnerabilities have been identified in the cups-filters package used in Red Hat Enterprise Linux versions 7 and 8.6. Notably, the libcupsfilters cfGetPrinterAttributes API does not sanitize returned IPP attributes (CVE-2024-47076), which could lead to security issues. Additional vulnerabilities include remote command injection via attacker-controlled data in PPD files and a DDoS amplification attack vector in cups-browsed. Red Hat has released security updates addressing these issues for affected versions.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The cups-filters package, which includes back ends, filters, and other software previously part of CUPS, contains several security flaws. CVE-2024-47076 concerns the libcupsfilters `cfGetPrinterAttributes` API failing to sanitize IPP attributes, potentially allowing malicious input to be processed unsafely. Other related vulnerabilities include cups-browsed binding to UDP INADDR_ANY:631 and accepting packets from any source (CVE-2024-47176), remote command injection via PPD files (CVE-2024-47175), and a DDoS amplification attack vector (CVE-2024-47850). Red Hat has issued security advisories and patches for these issues in their Enterprise Linux 7 Extended Lifecycle Support and 8.2 Advanced Update Support releases.
Potential Impact
The vulnerabilities could allow attackers to exploit unsanitized input in IPP attributes, potentially leading to unauthorized command execution or other malicious actions. The remote command injection vulnerability via PPD files could enable attackers to execute arbitrary commands. The cups-browsed UDP binding issue may allow attackers to send malicious packets, potentially leading to denial of service or amplification attacks. These issues collectively pose a significant security risk to affected systems running vulnerable versions of cups-filters.
Mitigation Recommendations
Red Hat has released official security updates for the cups-filters package addressing these vulnerabilities. Users should apply the updates provided for Red Hat Enterprise Linux 7 Extended Lifecycle Support and 8.2 Advanced Update Support as detailed in Red Hat advisories RHSA-2024:7553 and RHSA-2024:7461. Refer to https://access.redhat.com/articles/11258 for update instructions. Applying these patches mitigates the vulnerabilities. No additional vendor-recommended mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:7553
- Cve Count
- 4
- Additional Cves
- ["CVE-2024-47175","CVE-2024-47176","CVE-2024-47850"]
Threat ID: 6a3da1ed4853345fc18312d4
Added to database: 06/25/2026, 21:47:25 UTC
Last enriched: 08/06/2026, 23:24:45 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.