Multiple Vulnerabilities Disclosed in Linux-based CUPS Printing Service
ID: bdebc511-52d6-5289-8ab9-5a7e276145a5
STIX ID: report--bdebc511-52d6-5289-8ab9-5a7e276145a5
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs reports four newly disclosed vulnerabilities in CUPS and related libraries that allow attacker-controlled IPP attributes to be passed through, injected into PPD files, or used to achieve arbitrary command execution (notably via foomatic-rip). The researcher published technical details early; vendors are preparing patches. Because CUPS is typically not exposed to the public internet, Arctic Wolf assesses initial access risk as low but warns of realistic LAN lateral-movement exploitation; recommended mitigations include applying vendor patches, disabling cups-browsed if not needed, blocking outbound port 631, and inventorying devices listening on port 631.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
