Cups was due, too much functionality on too many systems, it needed to be more limited and secure by default.
Comment on Possible Linux Severe CVSS 9.9/10 Unauthenticated RCE Flaw
qqq@lemmy.world 1 month ago
This is a real exploit chain in cups-browsed
. The tl;dr is that it will add basically anything that knows the correct protocol to your printers, and this can be exploited for RCE if you print to the malicious printer. The service listens on all interfaces by default on UDP 631.
It is not as horrible as it was marketed, but it’s real. You may or may not have this service running by default; I didn’t on Fedora.
InvertedParallax@lemm.ee 1 month ago
style99@lemm.ee 1 month ago
Well, then…