Two Critical Vulnerabilities Found in PAPPL Affecting Local and Remote Code Execution
Article Content
Trend Micro's Zero Day Initiative has identified two significant vulnerabilities in the PAPPL printer software. The first, ZDI-CAN-32306, is a stack-based buffer overflow that allows local privilege escalation with a CVSS score of 7.8. The second, ZDI-CAN-32307, is a heap-based buffer overflow that enables remote code execution, rated at a CVSS score of 9.8. Both vulnerabilities affect the same version of PAPPL tested on Ubuntu 25.10. The vulnerabilities were discovered by an anonymous researcher and reported to the vendor, with a 120-day remediation timeline expected. If no patch is released within this period, Trend Micro will issue a limited public advisory with mitigations. The vulnerabilities pose a serious risk to users of PAPPL, particularly in environments where the software is deployed.
Key Points: • Two critical vulnerabilities in PAPPL identified by Trend Micro's Zero Day Initiative. • ZDI-CAN-32306 allows local privilege escalation; ZDI-CAN-32307 enables remote code execution. • Both vulnerabilities have a 120-day remediation timeline before public advisories are issued.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.