Missing Authorization in cups-browsed - CVE-2024-47176

 

Missing Authorization in cups-browsed - CVE-2024-47176

Published: September 27, 2024 / Updated: November 22, 2024


Vulnerability identifier: #VU97743
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47176
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization. A remote attacker can introduce a malicious printer to the system by sending specially crafted packets to port 631/UDP and then execute arbitrary OS commands on the system when a print job is started.


Affected software

cups-browsed
Debian Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Chrome OS
Event Processing
Netezza Appliance
IBM Event Endpoint Management
Business Automation Insights
watsonx Assistant for IBM Cloud Pak for Data
Watson CP4D Data Stores
Dell Hybrid Client
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cups-filters (Ubuntu package)
cups-browsed (Ubuntu package)
libpoppler-cpp0
libpoppler-qt4-4-debuginfo
libpoppler60
libpoppler-glib8
libpoppler-cpp0-debuginfo
libpoppler-glib-devel
libpoppler-devel
libpoppler-qt4-devel
typelib-1_0-Poppler-0_18
poppler-debugsource
poppler-tools-debuginfo
libpoppler60-debuginfo
libpoppler-qt4-4
poppler-tools
libpoppler-glib8-debuginfo
cups-filters (Red Hat package)
cups-filters
cups-filters-devel
cups-filters-libs
cups-filters-cups-browsed
cups-filters-cups-browsed-debuginfo
cups-filters-debuginfo
cups-filters-foomatic-rip-debuginfo
cups-filters-ghostscript-debuginfo
cups-filters-debugsource
cups-filters-foomatic-rip
cups-filters-ghostscript
cups-filters-doc
cups-filters-help
cups-filters (Debian package)
cups-browsed
libppd
libcupsfilters
cups-devel
cups-client
cups
cups-ipptool
cups-libs
cups-lpd
cups-doc
cups-filesystem
cups-help
cups-printerapp
cups-debugsource
cups-debuginfo
Event Streams
IBM Cloud Pak for Business Automation
Latitude 5450
Latitude 3330
Latitude 3440
Latitude 3450
Latitude 5440
OptiPlex 3000 Thin Client
OptiPlex 5400 All-In-One
OptiPlex 7010
Optiplex 7020
Optiplex 7410 All-in-One
Optiplex 7420 All-in-One
Precision 3280
Precision 3260

How to mitigate CVE-2024-47176

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Event Processing - update to 1.2.2
Netezza Appliance - update to 1.0.0.1
IBM Event Endpoint Management - update to 11.3.2
Event Streams - update to 11.5.1
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
cups-filters (Ubuntu package) - addressed in versions Ubuntu Pro, 1.27.4-1ubuntu0.3, 1.27.4-1ubuntu0.4, 1.28.15-0ubuntu1.3, 1.28.15-0ubuntu1.4
cups-browsed (Ubuntu package) - addressed in versions Ubuntu Pro, 1.27.4-1ubuntu0.3, 1.27.4-1ubuntu0.4, 1.28.15-0ubuntu1.3, 1.28.15-0ubuntu1.4, 2.0.0-0ubuntu10.1, 2.0.0-0ubuntu10.2, 2.0.1-0ubuntu2.1
libpoppler-cpp0 - update to 0.43.0-16.49.1
libpoppler-qt4-4-debuginfo - update to 0.43.0-16.49.1
libpoppler60 - update to 0.43.0-16.49.1
libpoppler-glib8 - update to 0.43.0-16.49.1
libpoppler-cpp0-debuginfo - update to 0.43.0-16.49.1
libpoppler-glib-devel - update to 0.43.0-16.49.1
libpoppler-devel - update to 0.43.0-16.49.1
libpoppler-qt4-devel - update to 0.43.0-16.49.1
typelib-1_0-Poppler-0_18 - update to 0.43.0-16.49.1
poppler-debugsource - update to 0.43.0-16.49.1
poppler-tools-debuginfo - update to 0.43.0-16.49.1
libpoppler60-debuginfo - update to 0.43.0-16.49.1
libpoppler-qt4-4 - update to 0.43.0-16.49.1
poppler-tools - update to 0.43.0-16.49.1
libpoppler-glib8-debuginfo - update to 0.43.0-16.49.1
cups-filters (Red Hat package) - addressed in versions 1.0.35-26.el7_7.3, 1.0.35-29.el7_9.3, 1.20.0-19.el8_2.2, 1.20.0-24.el8_4.2, 1.20.0-27.el8_6.3, 1.20.0-29.el8_8.3, 1.20.0-35.el8_10, 1.28.7-10.el9_0.2, 1.28.7-11.el9_2.2, 1.28.7-17.el9_4
cups-filters - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters-devel - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters-libs - addressed in versions 1.0.35-29, 1.20.0-35.0.1
cups-filters-cups-browsed - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters-cups-browsed-debuginfo - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1, 1.25.0-150200.3.16.1
cups-filters-debuginfo - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1, 1.25.0-150200.3.16.1
cups-filters-foomatic-rip-debuginfo - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters-ghostscript-debuginfo - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters-debugsource - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1, 1.25.0-150200.3.16.1
cups-filters-foomatic-rip - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters-ghostscript - addressed in versions 1.0.58-19.26.1, 1.0.58-19.29.1
cups-filters-doc - update to 1.20.0-35.0.1
cups-filters-devel - update to 1.25.0-150200.3.16.1
cups-filters - update to 1.28.9-5
cups-filters-debuginfo - update to 1.28.9-5
cups-filters-debugsource - update to 1.28.9-5
cups-filters-devel - update to 1.28.9-5
cups-filters-help - update to 1.28.9-5
cups-filters - update to 1.28.17
cups-filters (Debian package) - update to 1.28.17-3+deb12u1
cups-browsed - addressed in versions 2.0.1-3.fc39, 2.0.1-3.fc40
libppd - addressed in versions 2.1~b1-2.fc39, 2.1~b1-2.fc40
libcupsfilters - addressed in versions 2.1~b1-3.fc39, 2.1~b1-3.fc40
cups-devel - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-client - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-ipptool - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-libs - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-lpd - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-doc - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups-filesystem - addressed in versions 2.2.6-62.0.1, 2.2.6-64.0.1, 2.4.10-2
cups - addressed in versions 2.4.0-13, 2.4.7-5
cups-help - addressed in versions 2.4.0-13, 2.4.7-5
cups-filesystem - addressed in versions 2.4.0-13, 2.4.7-5
cups-printerapp - addressed in versions 2.4.0-13, 2.4.7-5
cups-lpd - addressed in versions 2.4.0-13, 2.4.7-5
cups-libs - addressed in versions 2.4.0-13, 2.4.7-5
cups-devel - addressed in versions 2.4.0-13, 2.4.7-5
cups-ipptool - addressed in versions 2.4.0-13, 2.4.7-5
cups-debugsource - addressed in versions 2.4.0-13, 2.4.7-5
cups-debuginfo - addressed in versions 2.4.0-13, 2.4.7-5
cups-client - addressed in versions 2.4.0-13, 2.4.7-5
cups-printerapp - update to 2.4.10-2
cups - addressed in versions 2.4.10-7.fc39, 2.4.10-7.fc40
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
Watson CP4D Data Stores - update to 5.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Chrome OS - update to 126.0.6478.254
Latitude 5450 - update to 2412
Dell Hybrid Client - update to 2412
Latitude 3330 - update to 2412
Latitude 3440 - update to 2412
Latitude 3450 - update to 2412
Latitude 5440 - update to 2412
OptiPlex 3000 Thin Client - update to 2412
OptiPlex 5400 All-In-One - update to 2412
OptiPlex 7010 - update to 2412
Optiplex 7020 - update to 2412
Optiplex 7410 All-in-One - update to 2412
Optiplex 7420 All-in-One - update to 2412
Precision 3280 - update to 2412
Precision 3260 - update to 2412

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins