Description
A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which can lead to a arbitrary code execution in a privileged service. To trigger the vulnerability, a malicious device would need to be connected to the vulnerable system over USB.
Problem types
CWE-121: Stack-based Buffer Overflow
Product status
Credits
Discovered by Aleksandar Nikolic of Cisco Talos.
References
talosintelligence.com/vulnerability_reports/TALOS-2024-2071