Cups Overflow: When your printer spills more than Ink
ID: 88a1c32b-cac7-5300-a989-49f53a20e87c
STIX ID: report--88a1c32b-cac7-5300-a989-49f53a20e87c
Feed Name: Elastic Security Labs
Threat Score
Elastic analyzes a disclosure of multiple critical CUPS vulnerabilities (several CVEs) that allow unauthenticated remote code execution via IPP and mDNS by registering malicious printers; the report reviews PoC exploitation (cupshax), impact across many UNIX-like systems, mitigation steps (disable cups-browsed, block UDP 631, patch CUPS), and provides detection and hunting rules to identify foomatic-rip/cupsd malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
