REDHAT-BUG-2316417: High severity cups vulnerability
Published Oct 4, 2024
·Updated
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)
Affected Software
1 affected component
apple CUPS<2.5b1
Event History
Oct 4, 2024
Data Sourced
via Red Hat·05:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2316417?
The severity of REDHAT-BUG-2316417 is classified as important.
2
How do I fix REDHAT-BUG-2316417?
To fix REDHAT-BUG-2316417, update CUPS to version 2.5b1 or later.
3
What systems are affected by REDHAT-BUG-2316417?
REDHAT-BUG-2316417 affects versions of Apple CUPS prior to 2.5b1.
4
What type of vulnerability is REDHAT-BUG-2316417?
REDHAT-BUG-2316417 is a vulnerability that allows sending HTTP POST requests to arbitrary destinations.
5
When was REDHAT-BUG-2316417 disclosed?
REDHAT-BUG-2316417 was disclosed recently as part of a Red Hat bug report.