CUPS cups-browsed before 2.5b1 will send an HTTP POST...
High severity
Unreviewed
Published
Oct 4, 2024
to the GitHub Advisory Database
•
Updated Oct 7, 2024
Description
Published by the National Vulnerability Database
Oct 4, 2024
Published to the GitHub Advisory Database
Oct 4, 2024
Last updated
Oct 7, 2024
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)
References