You are not logged in.

#1 2024-09-28 12:41:19

Colonel Panic
Member
Registered: 2018-11-13
Posts: 1,429

Severe security vulnerability in Cups

Hi everyone. Several sites I've seen today have said that a security vulnerability has been found in Cups which could potentially result in an attacker being able to take control of your computer;

https://www.redhat.com/en/blog/red-hat- … rabilities

My answer would be to remove cups-browsed (in fact I don't use Cups at all so could easily get rid of the whole thing too), but Red Hat have published a less drastic solution;

https://www.redhat.com/en/blog/red-hat- … rabilities

Last edited by Colonel Panic (2024-09-28 12:59:57)

Offline

#2 2024-09-28 12:42:43

altman
Member
From: Canada
Registered: 2015-10-24
Posts: 619

Re: Severe security vulnerability in Cups

Thx for that @Colonel Panic


My Linux installs are as in my music; it s on Metal

Offline

#3 2024-09-29 02:48:55

johnraff
nullglob
From: Nagoya, Japan
Registered: 2015-09-09
Posts: 12,652
Website

Re: Severe security vulnerability in Cups

cups-browsed helps to connect to a wifi-enabled printer without having to install any drivers. This works with modern printers and is something I'm making use of right now. roll
https://wiki.debian.org/CUPSDriverlessPrinting#Summary

There's a mitigation shown on Debian's security tracker:
https://security-tracker.debian.org/tra … 2024-47176

For client/desktop systems: Remove 'cups' from the "BrowseRemoteProtocols" line in /etc/cups/cups-browsed.conf and restart the cups-browsed service.

This seems to be what has been done in Debian's latest cups-filters upgrade - 1.28.17-5, currently in Sid, so should arrive in Bookworm and Trixie soon:
https://bugs.debian.org/cgi-bin/bugrepo … 1082820#10

I'm going to try that edit to /etc/cups/cups-browsed.conf and see if my wifi printer still works...

^EDIT: yes it still works. smile

Last edited by johnraff (2024-09-29 08:15:56)


...elevator in the Brain Hotel, broken down but just as well...
( a boring Japan blog (currently paused), now on Bluesky, there's also some GitStuff )

Introduction to the Bunsenlabs Boron Desktop

Offline

#4 2024-09-30 01:57:34

johnraff
nullglob
From: Nagoya, Japan
Registered: 2015-09-09
Posts: 12,652
Website

Re: Severe security vulnerability in Cups

The fixed version of cups-filters has arrived, and for Bookworm it's 1.28.17-3+deb12u1, not 1.28.17-5 as I posted above - that one's for Sid.


...elevator in the Brain Hotel, broken down but just as well...
( a boring Japan blog (currently paused), now on Bluesky, there's also some GitStuff )

Introduction to the Bunsenlabs Boron Desktop

Offline

#5 2024-09-30 16:56:11

DeepDayze
Like sands through an hourglass...
From: In Linux Land
Registered: 2017-05-28
Posts: 1,901

Re: Severe security vulnerability in Cups

Removing 'cups' from the "BrowseRemoteProtocols" line in /etc/cups/cups-browsed.conf and either restarting the service or rebooting works for me as well.


Real Men Use Linux

Offline

#6 2024-09-30 21:04:26

Sector11
Mod Squid Tpyo Knig
From: Upstairs
Registered: 2015-08-20
Posts: 8,028

Re: Severe security vulnerability in Cups

My hammer and chisel¹ were not affected.

I don't trust WiFi or bluetooth much.

¹ printer on a cable.


Debian 12 Beardog, SoxDog and still a Conky 1.9er

Offline

#7 2024-10-08 12:59:06

novice
Member
Registered: 2020-01-30
Posts: 61

Re: Severe security vulnerability in Cups

Edit: Never mind, I've just seen how to disable it.
Is there any other way to disable it? That line in my cups-browsed.conf doesn't have cups in it, but cups-browsed is running on my machine.

Last edited by novice (2024-10-08 13:00:55)

Offline

#8 2024-10-09 02:34:28

johnraff
nullglob
From: Nagoya, Japan
Registered: 2015-09-09
Posts: 12,652
Website

Re: Severe security vulnerability in Cups

^If the config line has been correctly edited then it should be safe to have cups-browsed running. It does in fact have some use. But if you don't need it, then just uninstall the package cups-browsed.


...elevator in the Brain Hotel, broken down but just as well...
( a boring Japan blog (currently paused), now on Bluesky, there's also some GitStuff )

Introduction to the Bunsenlabs Boron Desktop

Offline

#9 2024-10-09 15:41:16

novice
Member
Registered: 2020-01-30
Posts: 61

Re: Severe security vulnerability in Cups

Thanks. I assume I don't need it. I only print from one machine and the printer is connected by USB cable.

Offline

Board footer

Powered by FluxBB