CVE-2023-4504 | OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow

Exp

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

Published: 2023-09-21 Last update: 2025-11-04 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-4504 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2023-4504

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2023-4504

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-21 0.18% 0.04% -0.14%
2 2025-11-18 0.04% 0.18% +0.14%
3 2025-04-15 0.04%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-4504

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.0 3.1 HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.0 5.9 [email protected]
7.0 3.1 HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.0 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2023-4504

OS Trackers for CVE-2023-4504

vendor priority summary link
alpine CVE-2023-4504: 1 source package rows (cups); 43 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 36. https://security.alpinelinux.org/vuln/CVE-2023-4504
debian unimportant CVE-2023-4504 unimportant priority: Debian including 2 source packages (cups, libppd), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7. https://security-tracker.debian.org/tracker/CVE-2023-4504
gentoo high CVE-2023-4504: 1 GLSA(s) (202402-17), 1 atom(s) (net-print/cups); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-4504
redhat medium https://access.redhat.com/security/cve/CVE-2023-4504
suse high CVE-2023-4504 severity important: SUSE including 285 source package names (6.0-baremetal:glibc-2.38-slfo.1.1_4.1, 6.0-base:glibc-2.38-slfo.1.1_4.1, …), 953 product×package rows across 255 product lines (Container rancher/elemental-channel/sl-micro, Container suse/kiosk/firefox-esr, … (255 product lines)): Fixed 778, Known Affected 175. https://www.suse.com/security/cve/CVE-2023-4504/
ubuntu medium CVE-2023-4504 medium priority: Ubuntu including 2 source packages (cups, libppd), 24 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 16, needs-triage 6, ignored 2. https://ubuntu.com/security/CVE-2023-4504

Affected software / configurations for CVE-2023-4504

Vendor Product Version Raw CPE
openprinting cups < 2.4.7 cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
openprinting libppd 2.0 cpe:2.3:a:openprinting:libppd:2.0:rc2:*:*:*:linux:*:*
fedoraproject fedora 37 cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
fedoraproject fedora 38 cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
fedoraproject fedora 39 cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
debian debian_linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

References for CVE-2023-4504

URL Tags
https://github.com/OpenPrinting/cups/releases/tag/v2.4.7 Release Notes
https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678h Exploit Vendor Advisory
https://github.com/OpenPrinting/libppd/security/advisories/GHSA-4f65-6ph5-qwh6 Exploit Vendor Advisory
https://lists.debian.org/debian-lts-announce/2023/09/msg00041.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/5WHEJIYMMAIXU2EC35MGTB5LGGO2FFJE/ Mailing List Release Notes
https://lists.fedoraproject.org/archives/list/[email protected]/message/5WVS4I7JG3LISFPKTM6ADKJXXEPEEWBQ/ Mailing List Release Notes
https://lists.fedoraproject.org/archives/list/[email protected]/message/AMYDKIE4PSJDEMC5OWNFCDMHFGLJ57XG/ Mailing List Release Notes
https://lists.fedoraproject.org/archives/list/[email protected]/message/PXPVADB56NMLJWG4IZ3OZBNJ2ZOLPQJ6/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/T2GSPQAFK2Z6L57TRXEKZDF42K2EVBH7/ Mailing List Release Notes
https://takeonme.org/cves/CVE-2023-4504.html Exploit
http://seclists.org/fulldisclosure/2024/Sep/33
cvelogic Threat Intelligence