CVE-2023-4504 is a heap-based buffer overflow in CUPS and libppd when processing PostScript Printer Description (PPD) documents. The flaw results from failure to validate a length supplied in an attacker-crafted PPD PostScript document, permitting memory corruption and potentially code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a proof-of-concept (POC) exploit for CVE-2023-4504, a heap-based buffer overflow in the scan_ps() function of CUPS version 2.4.6. The repository contains two C source files: 'replicate.c' (the vulnerable/POC code) and 'fixed.c' (a mock fixed version). The exploit is triggered by a specially crafted input buffer that simulates malformed PostScript data, and a malicious PPD file ('malicious.ppd') is provided to facilitate testing with a dummy printer in CUPS. The 'instructions.txt' file details how to set up a vulnerable CUPS environment, compile the code, and link the malicious PPD file to a printer for testing. The exploit does not provide a shell or direct code execution, but demonstrates the memory corruption that could be leveraged for further exploitation. The attack vector is local, requiring the attacker to have the ability to submit print jobs or PPD files to the CUPS server. No network endpoints or remote services are directly targeted. The repository is structured for educational and research purposes, illustrating both the vulnerability and a potential fix.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Important-severity locally exploitable vulnerability affecting an AlmaLinux 9.6 package covered by the referenced TuxCare security advisory. The supplied CVSS v3 vector indicates local access, high attack complexity, no privileges required, user interaction required, and high impact to confidentiality, integrity, and availability.
A specific vulnerability tracked as CVE-2023-4504 affecting the Rocky Linux 9.6/TuxCare advisory context. The supplied record characterizes it as a local, high-impact issue requiring high attack complexity and user interaction, with exploits available.
An important-severity vulnerability referenced by an Alma Linux 9.2 local-security-check plugin. It has CVSS v3 vector AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; the plugin states exploits are available and a patch was published.
A vulnerability referenced by the CentOS local security-check plugin, rated Important. The plugin reports that exploits are available and a patch was published.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.