That doomsday critical Linux bug: It's CUPS. May lead to remote hijacking of devices
ID: d6b1f410-5e2e-54b4-9bc1-262fa075cc83
STIX ID: report--d6b1f410-5e2e-54b4-9bc1-262fa075cc83
Feed Name: The Register (Security)
A public write-up details a chained set of vulnerabilities in the Unix printing system CUPS (four CVEs) that allow an attacker to replace or install printer IPP URLs and inject malicious PPD content, leading to arbitrary command execution when a user initiates a print job; exploitation requires network reachability to UDP/631 or LAN advertisement spoofing and user interaction to trigger the job. The researcher advised disabling cups-browsed, blocking UDP 631 and DNS‑SD/mDNS, and applying vendor patches when available; distributions like Ubuntu have issued advisories and mitigations are recommended immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
