Simone Margaritelli discovered that cups-browsed could be used to create arbitrary printers from outside the local network. In combination with issues in other printing components, a remote attacker could possibly use this issue to connect to a system, created manipulated PPD files, and execute arbitrary code when a printer is used. This update disables support for the legacy CUPS printer discovery protocol.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.0.0-0ubuntu10.1", "binary_name": "cups-browsed" }, { "binary_version": "2.0.0-0ubuntu10.1", "binary_name": "cups-browsed-dbgsym" }, { "binary_version": "2.0.0-0ubuntu10.1", "binary_name": "cups-browsed-tests" } ] }