▲ 42 ▼ Critical Unauthenticated RCE Flaws in CUPS Printing Systems (blog.qualys.com) submitted 2 years ago by Toes@ani.social to c/linux@programming.dev 9 comments fedilink hide all child comments cross-posted from: https://ani.social/post/6217644
[–] curbstickle@lemmy.dbzer0.com -1 points 2 years ago (3 children) Yes. Its nowhere near the risk that was claimed. permalink fedilink source parent hideshow 3 child comments replies: [–] Toes@ani.social [S] 4 points 2 years ago (2 children) Basically an unauthenticated perl interpreter with root open to the network by default in most configurations across a couple decades. It's about as bad as it can be? permalink fedilink source parent hideshow 2 child comments replies: [–] curbstickle@lemmy.dbzer0.com 3 points 2 years ago Compared to the original claim that it was kernel level and spread across literally everything? No, no its not as bad as it was originally claimed. Is it bad? Yes. Is it kernel level bad? No. It can easily be mitigated before a fix is out by blocking 631 and dns-sd traffic. It is not as bad as it was claimed to be. permalink fedilink source parent [–] progandy@feddit.org 1 point 2 years ago Is it common for cups to run as root? It should have its own user, but that is still not good. permalink fedilink source parent
[–] Toes@ani.social [S] 4 points 2 years ago (2 children) Basically an unauthenticated perl interpreter with root open to the network by default in most configurations across a couple decades. It's about as bad as it can be? permalink fedilink source parent hideshow 2 child comments replies: [–] curbstickle@lemmy.dbzer0.com 3 points 2 years ago Compared to the original claim that it was kernel level and spread across literally everything? No, no its not as bad as it was originally claimed. Is it bad? Yes. Is it kernel level bad? No. It can easily be mitigated before a fix is out by blocking 631 and dns-sd traffic. It is not as bad as it was claimed to be. permalink fedilink source parent [–] progandy@feddit.org 1 point 2 years ago Is it common for cups to run as root? It should have its own user, but that is still not good. permalink fedilink source parent
[–] curbstickle@lemmy.dbzer0.com 3 points 2 years ago Compared to the original claim that it was kernel level and spread across literally everything? No, no its not as bad as it was originally claimed. Is it bad? Yes. Is it kernel level bad? No. It can easily be mitigated before a fix is out by blocking 631 and dns-sd traffic. It is not as bad as it was claimed to be. permalink fedilink source parent
[–] progandy@feddit.org 1 point 2 years ago Is it common for cups to run as root? It should have its own user, but that is still not good. permalink fedilink source parent