CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limit…
CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the `Get-Printer-Attributes` IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.
The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
https://cwe.mitre.org/data/definitions/1327.html →Open in CWE collection →The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://cwe.mitre.org/data/definitions/862.html →Open in CWE collection →The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
https://cwe.mitre.org/data/definitions/940.html →Open in CWE collection →In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. An attacker with the ability to access functionality not properly constrained by ACLs can obtain sensitive information and possibly compromise the entire application. Such an attacker can access resources that must be available only to users at a higher privilege level, can access management sections of the application, or can run queries for data that they otherwise not supposed to.
https://capec.mitre.org/data/definitions/1.html →Open in CAPEC collection →An adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView component. Through the injected code, an adversary is able to manipulate the DOM tree and cookies of the page, expose sensitive information, and can launch attacks against the web application from within the web page.
https://capec.mitre.org/data/definitions/500.html →Open in CAPEC collection →An adversary injects traffic into the target's network connection. The adversary is therefore able to degrade or disrupt the connection, and potentially modify the content. This is not a flooding attack, as the adversary is not focusing on exhausting resources. Instead, the adversary is crafting a specific input to affect the system in a particular way.
https://capec.mitre.org/data/definitions/594.html →Open in CAPEC collection →In this attack pattern, an adversary injects a connection reset packet to one or both ends of a target's connection. The attacker is therefore able to have the target and/or the destination server sever the connection without having to directly filter the traffic between them.
https://capec.mitre.org/data/definitions/595.html →Open in CAPEC collection →An adversary injects one or more TCP RST packets to a target after the target has made a HTTP GET request. The goal of this attack is to have the target and/or destination web server terminate the TCP connection.
https://capec.mitre.org/data/definitions/596.html →Open in CAPEC collection →https://capec.mitre.org/data/definitions/665.html →Open in CAPEC collection →
| Product | Vendor | Status |
|---|---|---|
| Tracked | ||
| cups-browsed | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked | |
| cups-filters | Tracked |