Re: [cochiselinux] [security] Ubuntu Patches ‘Severe’ Security Flaw in CUPS

1 message · started by Rex Bouwense on Sep 27, 2024

Re: [cochiselinux] [security] Ubuntu Patches ‘Severe’ Security Flaw in CUPS

From Rex Bouwense · Sep 27, 2024

If you are using Ubuntu or one of its "flavors" that CUPS Security
Vulnerability has already been patched, providing you keep your system
updated.

Rex

On 9/26/24 19:15, Devi Garcia wrote:
Quoted reply (34 lines)
The CUPS Security Vulnerability
Canonical explains in its security blog: “At its core, the 
vulnerability is exploited by tricking CUPS into generating an 
The CUPS Security Vulnerability
Canonical explains in its security blog: “At its core, the 
vulnerability is exploited by tricking CUPS into generating an 
attacker-controlled PPD (PostScript Printer Description) file for a 
printer containing an arbitrary command.”

“Whenever the next print job is sent to the printer in question, the 
command will be executed as the lp user (this is the user that the 
CUPS daemon runs as and, barring other exploitable vulnerabilities, 
would not have escalated privileges).”

Many headline-grabbing security vulnerabilities often affect specific 
hardware or configurations, or require a ne’er-do-well to have 
physical access to your machine to work.

You might think, “No worries! No one will trick a printing service on 
my computer into doing things without I don’t know about.”

But Simone Margaritelli, who uncovered the flaw and had to battle to 
get it taken as seriously as he felt it was, explains in a detailed 
write up on his blog that this can be done silently, remotely, and 
without authentication.

On the internet “a remote attacker sends an UDP packet to port 631. No 
authentication whatsoever,” or on a LAN, “spoofs zeroconf / mDNS / 
DNS-SD advertisements”.

read article:
https://www.omgubuntu.co.uk/2024/09/ubuntu-secuity-fix-cups-vulnerability
--------------------------------------------------------------------
Cochise Linux Users Group Mailing List - cochiselinux@freelists.org
For more information:  https://cochiselinuxusergroup.org/
Mailing List Archive: https://www.freelists.org/archive/cochiselinux
To unsubscribe: //www.freelists.org/list/cochiselinux

View original on FreeLists


Previous thread · Next thread

Back to September 2024