logo

Multiple Vulnerabilities Disclosed in Linux-based CUPS Printing Service

ID: af8b445f-5505-5c1c-8c2b-5c20e5b3a86d

STIX ID: report--af8b445f-5505-5c1c-8c2b-5c20e5b3a86d

Feed Name: Arctic Wolf

Threat Score
55/100

Date Published: 2024-09-27

Date Updated: 2026-07-25

Author: Stefan Hostetler

...
...

On 26 September 2024 a researcher disclosed four CUPS vulnerabilities affecting GNU/Linux distributions (CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177) that enable attacker-controlled IPP requests, unsanitised IPP attributes to flow through CUPS, PPD file injection, and arbitrary command execution via foomatic-rip; vendors were notified and patches are being prepared, the researcher released details early after an embargo leak, Arctic Wolf assesses low risk of internet-based initial access but notes plausible LAN lateral movement and recommends patching, blocking outbound port 631, disabling cups-browsed where possible, and inventorying hosts listening on port 631.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.