-
Notifications
You must be signed in to change notification settings - Fork 10
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Removed support for legacy CUPS browsing and for LDAP
Legacy CUPS browsing is not needed any more. this functionality got removed from CUPS with version 1.6, more than a decade ago. In cups-browsed it was implemented as a legacy support layer for servers or clients running long-term-support enterprise distributions still using CUPS 1.5.x or older. Now the support life of all these distributions should have expired and so this legacy support by cups-browsed is not needed any more. In addition, the legacy CUPS browsing implementation in cups-browsed was listening for UDP packaets on port 631 and by default it accepted packets from any source, making it easy for attackers to set up forged printers which could make use of vulnerabilities of CUPS or just find out about the identity and properties of clients. This is CVE-2024-47176: https://ubuntu.com/security/CVE-2024-47176 GHSA-rj88-6mr5-rcw8 https://openprinting.github.io/OpenPrinting-News-Flash-cups-browsed-Remote-Code-Execution-vulnerability/ The removal of the legacy CUPS browsing support removes also this vulnerability. The LDAP implementation in cups-browsed does not follow the LDAP printer schema RFC 7612 and is therefore of very limited use.
- Loading branch information
1 parent
0b8d168
commit 1d1072a
Showing
8 changed files
with
138 additions
and
1,751 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.