First published: Wed Oct 09 2024(Updated: )
USN-7042-1 fixed a vulnerability in cups-browsed. This update improves the fix by removing support for the legacy CUPS printer discovery protocol entirely. Original advisory details: Simone Margaritelli discovered that cups-browsed could be used to create arbitrary printers from outside the local network. In combination with issues in other printing components, a remote attacker could possibly use this issue to connect to a system, created manipulated PPD files, and execute arbitrary code when a printer is used. This update disables support for the legacy CUPS printer discovery protocol.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/cups-browsed | <2.0.0-0ubuntu10.2 | 2.0.0-0ubuntu10.2 |
Ubuntu Ubuntu | =24.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.