Cups · Cups Cups-Browsed · CVE-2024-47850
**Name of the Vulnerable Software and Affected Versions**
CUPS cups-browsed versions prior to 2.5b1
**Description**
The issue is related to an uncontrolled resource consumption in the CUPS cups-browsed service, which can be exploited by a remote attacker to cause a denial of service. It is also associated with a DDoS amplification attack, where the service sends an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added.
**Recommendations**
For versions prior to 2.5b1, update to version 2.5b1 or later to resolve the issue. As a temporary workaround, consider restricting access to the cups-browsed service to minimize the risk of exploitation. Avoid using the service to probe new printers until the issue is resolved.