20240927200942-cups vulnerability remote execution
There was a new vulnerability disclosed for the printing system in linux.
If I understand it correctly it needs local network access for the open port and a user that can print to print. And then it would allow access to the system as lp
From the original blog post:
I used the only platform I had plus a pinch of drama as a tool to have them fucking re-prioritize. And it worked, wonderfully, more fixes happened after two tweets than with all the arguing and talking, so :shrug:.
I ran systemctl disable --now cups-browsed
on the debian server
[[]]