CUPS flaws enable Linux remote code execution, but there’s a catch
ID: 7f09bd5d-379a-551c-a81f-2f3de354634e
STIX ID: report--7f09bd5d-379a-551c-a81f-2f3de354634e
Feed Name: Bleeping Computer
A security researcher disclosed four linked CUPS vulnerabilities that can lead to remote code execution when the cups-browsed daemon is enabled and a user prints to a maliciously advertised printer; the attack abuses a foomatic-rip filter in a crafted PPD. Impact is limited because cups-browsed is often disabled by default and exploitation requires local-network access and user interaction; Red Hat rates the issues as Important and recommends stopping/disabling cups-browsed as a mitigation while patches are developed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
