跳转到帖子

Ubuntu: (CVE-2024-47850): cups-browsed vulnerability

recommended_posts

发布于
  • Members

Ubuntu: (CVE-2024-47850): cups-browsed vulnerability

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
10/04/2024
Created
11/21/2024
Added
11/19/2024
Modified
11/19/2024

Description

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)

Solution(s)

  • ubuntu-pro-upgrade-cups-browsed
  • ubuntu-pro-upgrade-cups-filters

References

  • https://attackerkb.com/topics/cve-2024-47850
  • CVE - 2024-47850
  • https://github.com/OpenPrinting/cups
  • https://github.com/advisories/GHSA-phc2-g348-384g
  • https://ubuntu.com/blog/cups-remote-code-execution-vulnerability-fix-available
  • https://ubuntu.com/security/notices/USN-7042-1
  • https://ubuntu.com/security/notices/USN-7043-1
  • https://ubuntu.com/security/notices/USN-7043-2
  • https://ubuntu.com/security/notices/USN-7043-3
  • https://www.akamai.com/blog/security-research/october-cups-ddos-threat
  • https://www.cve.org/CVERecord?id=CVE-2024-47850
  • https://www.openwall.com/lists/oss-security/2024/10/04/1
View more
  • 查看数 709
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…