{"id":"USN-7042-3","summary":"cups-browsed vulnerability","details":"USN-7042-2 released an improved fix for cups-browsed. This update provides\nthe corresponding update for Ubuntu 24.10.\n\nOriginal advisory details:\n\n Simone Margaritelli discovered that cups-browsed could be used to create\n arbitrary printers from outside the local network. In combination with\n issues in other printing components, a remote attacker could possibly use\n this issue to connect to a system, created manipulated PPD files, and\n execute arbitrary code when a printer is used. This update disables\n support for the legacy CUPS printer discovery protocol.\n","modified":"2026-01-30T00:59:09.738320Z","published":"2024-10-21T12:33:17.888114Z","related":["CVE-2024-47176","UBUNTU-CVE-2024-47176"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7042-3"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-47176"}],"affected":[{"package":{"name":"cups-browsed","ecosystem":"Ubuntu:24.10","purl":"pkg:deb/ubuntu/cups-browsed@2.0.1-0ubuntu2.1?arch=source&distro=oracular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1-0ubuntu2.1"}]}],"versions":["2.0.0-0ubuntu10","2.0.1-0ubuntu1","2.0.1-0ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.0.1-0ubuntu2.1","binary_name":"cups-browsed"},{"binary_name":"cups-browsed-dbgsym","binary_version":"2.0.1-0ubuntu2.1"},{"binary_name":"cups-browsed-tests","binary_version":"2.0.1-0ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7042-3.json"}}],"schema_version":"1.7.3"}