[security] Ubuntu Patches ‘Severe’ Security Flaw in CUPS

1 message · started by Devi Garcia on Sep 26, 2024

[security] Ubuntu Patches ‘Severe’ Security Flaw in CUPS

From Devi Garcia · Sep 26, 2024

The CUPS Security Vulnerability
Canonical explains in its security blog: “At its core, the vulnerability is exploited by tricking CUPS into generating an attacker-controlled PPD (PostScript Printer Description) file for a printer containing an arbitrary command.”

“Whenever the next print job is sent to the printer in question, the command will be executed as the lp user (this is the user that the CUPS daemon runs as and, barring other exploitable vulnerabilities, would not have escalated privileges).”

Many headline-grabbing security vulnerabilities often affect specific hardware or configurations, or require a ne’er-do-well to have physical access to your machine to work.

You might think, “No worries! No one will trick a printing service on my computer into doing things without I don’t know about.”

But Simone Margaritelli, who uncovered the flaw and had to battle to get it taken as seriously as he felt it was, explains in a detailed write up on his blog that this can be done silently, remotely, and without authentication.

On the internet “a remote attacker sends an UDP packet to port 631. No authentication whatsoever,” or on a LAN, “spoofs zeroconf / mDNS / DNS-SD advertisements”.

read article:

View original on FreeLists


Previous thread · Next thread

Back to September 2024