USN-7042-3: cups-browsed vulnerability
USN-7042-2 released an improved fix for cups-browsed. This update provides the corresponding update for Ubuntu 24.10. Original advisory details: Simone Margaritelli discovered that cups-browsed could be used to create arbitrary printers from outside the local network. In combination with issues in other printing components, a remote attacker could possibly use this issue to connect to a system, created manipulated PPD files, and execute arbitrary code when a printer is used. This update disables support for the legacy CUPS printer discovery protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7042-3?
USN-7042-3 addresses a significant vulnerability in cups-browsed that allows arbitrary printer creation from external networks.
How do I fix USN-7042-3?
To fix USN-7042-3, update the cups-browsed package to version 2.0.1-0ubuntu2.1 on Ubuntu 24.10.
What versions of Ubuntu are affected by USN-7042-3?
USN-7042-3 specifically affects Ubuntu version 24.10.
What component does USN-7042-3 affect?
USN-7042-3 affects the cups-browsed component within the Ubuntu operating system.
Who discovered the vulnerability in USN-7042-3?
The vulnerability addressed in USN-7042-3 was discovered by Simone Margaritelli.