cross-posted from: https://lemmy.zip/post/23601247

I hope this goes without saying but please do not run this on machines you don’t own.

The good news:

  • the exploit seems to require user action

The bad news:

  • Device Firewalls are ineffective against this

  • if someone created a malicious printer on a local network like a library they could create serious issues

  • it is hard to patch without breaking printing

  • it is very easy to create printers that look legit

  • even if you don’t hit print the cups user agent can reveal lots of information. This may be blocked at the Firewall

TLDR: you should be careful hitting print

  • Vivendi
    link
    fedilink
    arrow-up
    14
    arrow-down
    1
    ·
    3 months ago

    If there is ONE project that needs a rewrite in modern C++ OR Rust (or some other ‘safe’ language) it’s FUCKING CUPS

    Please, Rust fanatics, do ONE good instead of rewriting GPL programs into a corpo-rat license