sweng@programming.devtoLinux@lemmy.ml•OpenPrinting News Flash - cups-browsed Remote Code Execution vulnerability
0·
2 months agoI’m not sure why you say it’s “artificially” inflated. Non-linux systems are also affected.
I’m not sure why you say it’s “artificially” inflated. Non-linux systems are also affected.
this will affect almost nobody
Is that really true? From https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
Full disclosure, I’ve been scanning the entire public internet IPv4 ranges several times a day for weeks, sending the UDP packet and logging whatever connected back. And I’ve got back connections from hundreds of thousands of devices, with peaks of 200-300K concurrent devices.
You would be vulnerable on Windows, if you were running CUPS, which you probably are not. But CUPS is not tied to Linux, and is used commonly on e.g. BSDs, and Apple has their own fork for MacOS (have not heard anything about it being vulnerable though).