Printing vulnerability affecting Linux distros raises alarm | Computer Weekly
Summary
A newly discovered series of four dangerous flaws in the Common Unix Printing System (Cups), which is used across virtually all GNU/Linux distros including Debian, Red Hat and SUSE, as well as Apple macOS and Google Chrome/Chromium among other things, is causing alarm bells to ring for security professionals over the potential scope of the problem. Saeed Abbasi, product manager for the Qualys Threat Research Unit, said: “These vulnerabilities enable a remote unauthenticated attacker to replace existing printers’ IPP URLs with malicious ones silently. “I understand the logic in phasing out disclosure, as this vulnerability will take time to find and fix, however, we should also expect threat actors to be scrutinising the commit history and looking for clues to exploit. Cancel your vacations … it could be a race against attackers.” The research team at JFrog, however, took an opposing view and held off on characterising the Cups vulnerabilities as a Log4Shell-style event, saying they believed the exploitation prerequisites are actually not that common. Sentry’s Chad Whitacre says a more thoughtful approach is needed to balance the individual freedom and creativity of open source, with more rigorous security practice.