Note:
This CVE has been split from CVE-2024-4712.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49152 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can be used to flood disk space and result in a Denial of Service (DoS) attack. Note: This CVE has been split from CVE-2024-4712. |
| Link | Providers |
|---|---|
| https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/ |
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 03 Oct 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Papercut
Papercut papercut Mf Papercut papercut Ng |
|
| CPEs | cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Papercut
Papercut papercut Mf Papercut papercut Ng |
Thu, 26 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Sep 2024 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can be used to flood disk space and result in a Denial of Service (DoS) attack. Note: This CVE has been split from CVE-2024-4712. | |
| Title | Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attack | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2024-09-26T15:02:10.145Z
Reserved: 2024-09-04T05:55:45.849Z
Link: CVE-2024-8405
Updated: 2024-09-26T15:02:05.465Z
Status : Analyzed
Published: 2024-09-26T02:15:03.007
Modified: 2024-10-03T00:51:18.313
Link: CVE-2024-8405
No data.
OpenCVE Enrichment
No data.
EUVD