[GTALUG] serious RCE vulnerability via CUPS

D. Hugh Redelmeier hugh at mimosa.com
Sat Sep 28 10:39:05 EDT 2024


> From: D. Hugh Redelmeier via talk <talk at gtalug.org>

> I don't know why anyone thought a big codebase like CUPS ought to run as 
> root.  Even after these fixes, the question remains.

Red Hat says that on its systems, cups-browserd runs as the unprivileged 
user "lp".

<https://access.redhat.com/security/vulnerabilities/RHSB-2024-002>


More information about the talk mailing list