First published: Thu Sep 26 2024(Updated: )
Simone Margaritelli discovered that the cups-filters cups-browsed component could be used to create arbitrary printers from outside the local network. In combination with issues in other printing components, a remote attacker could possibly use this issue to connect to a system, created manipulated PPD files, and execute arbitrary code when a printer is used. This update disables support for the legacy CUPS printer discovery protocol. (CVE-2024-47176) Simone Margaritelli discovered that cups-filters incorrectly sanitized IPP data when creating PPD files. A remote attacker could possibly use this issue to manipulate PPD files and execute arbitrary code when a printer is used. (CVE-2024-47076)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/cups-browsed | <1.28.15-0ubuntu1.3 | 1.28.15-0ubuntu1.3 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/cups-filters | <1.28.15-0ubuntu1.3 | 1.28.15-0ubuntu1.3 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/cups-browsed | <1.27.4-1ubuntu0.3 | 1.27.4-1ubuntu0.3 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/cups-filters | <1.27.4-1ubuntu0.3 | 1.27.4-1ubuntu0.3 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.