First published: Fri Oct 04 2024(Updated: )
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than <a href="https://access.redhat.com/security/cve/CVE-2024-47176">CVE-2024-47176</a>. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple CUPS | <2.5b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47850 is considered a high-severity vulnerability due to its potential for abuse in sending arbitrary HTTP requests.
To fix CVE-2024-47850, update to CUPS version 2.5b1 or later as it addresses this vulnerability.
CVE-2024-47850 affects versions of Apple CUPS prior to 2.5b1.
The risks of CVE-2024-47850 include potential unauthorized requests being sent to arbitrary destinations, leading to data exposure or service disruption.
Yes, CVE-2024-47850 can be exploited remotely via IPP UDP packets.