Alerts This Week
Warning Icon 1 1,020
Alerts This Week
Warning Icon 1 1,020

Ubuntu 24.10 USN-7042-3 critical: cups-browsed network exploit

ubuntu
Calendar Grey October 21, 2024
Dist Ubuntu Esm H88
The Ubuntu Security Notice USN-7042-3 highlights a vulnerability related to cups-browsed that could permit unauthorized execution of applications through specially crafted network packets.
cups-browsed could be made to run programs if it received specially crafted network traffic.

Summary

cups-browsed could be made to run programs if it received specially crafted

network traffic.

Software Description:

- cups-browsed: OpenPrinting cups-browsed

Details:

USN-7042-2 released an improved fix for cups-browsed. This update provides

the corresponding update for Ubuntu 24.10.

Original advisory details:

Simone Margaritelli discovered that cups-browsed could be used to create

arbitrary printers from outside the local network. In combination with

issues in other printing components, a remote attacker could possibly use

this issue to connect to a system, created manipulated PPD files, and

execute arbitrary code when a printer is used. This update disables

support for the legacy CUPS printer discovery protocol.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   cups-browsed                    2.0.1-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7042-3

https://ubuntu.com/security/notices/USN-7042-2

https://ubuntu.com/security/notices/USN-7042-1

CVE-2024-47176

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7042-3

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here