Simone Margaritelli, OpenSnitch firewall and bettercap network analyzer author, prematurely disclosed information about previously announced critical vulnerabilities that allow remote attacks on GNU/Linux, Solaris, FreeBSD distributions, and some other BSD systems. The publication was originally scheduled for October 6, but due to information leakage, it had to be released ahead of time before most distributions could prepare package updates. The vulnerabilities affect the CUPS print server and allow remote code execution on the system without authentication.
The researcher who identified the issue prepared a working exploit prototype that uses a combination of several vulnerabilities, allowing remote code execution with the privileges of the CUPS print job processing user (usually the ‘lp’ user). The exploit enables the attacker to stealthily change user printer settings or add a new printer linked to a running attacking IPP server that provides a specially formatted PPD printer description. Processing this PPD during print job initiation results in executing the attacker's code (it is necessary for the victim to initiate printing on the spoofed or replaced printer).
Systems with server CUPS printing and the running cups-browsed process, which accepts network connections on port 631 (UDP), are vulnerable. The attack can also originate from a local network where protocols such as zeroconf, mDNS, or DNS-SD are used for access to sunucunuz printing. Only cups-browsed configurations where the BrowseRemoteProtocols parameter in the /etc/cups/cups-browsed.conf file is set to ‘cups’ are vulnerable. On distributions with systemd, the status of the cups-browsed service can be checked with the command ‘sudo systemctl status cups-browsed’.
The vulnerability manifests in all CUPS-based printing systems using vulnerable versions of the cups-filters, libcupsfilters, libppd, and cups-browsed packages. Fixes are currently available only in the form of patches (1, 2, 3) — the relevant versions of cups-filters 2.0.1, libcupsfilters 2.1b1, libppd 2.1b1, and cups-browsed 2.0.1 are susceptible to the vulnerabilities. The issue remains unpatched in distributions, and updates can be monitored on the following pages: Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD. As a workaround for protection until the update is installed, access to UDP port 631 can be restricted from external networks, the cups-browsed service disabled, or the BrowseRemoteProtocols setting changed to ‘none’.
Aşkar edilmiş zəifliklər:
- CVE-2024-47176 — CUPS-browsed prosesinde bir zafiyet, 631 numaralı portta bağlantılar kabul eden bir ağ soketi oluşturarak sistemdeki tüm ağ ara yüzlerine bağlıdır ve harici sistemlerden "Get-Printer-Attributes" IPP isteklerini almaktadır. Bu servisi manipüle ederek, saldırgan tarafından kontrol edilen bir yazıcıyı sisteme eklemek ve CUPS'ın diğer bileşenlerindeki zafiyetleri istismar etmek mümkündür.
- CVE-2024-47177 — cups-filters paketindeki foomatic-rip işleyicisinde bir zafiyet, saldırganın yukarıda belirtilen CUPS-browsed zafiyetini kullanarak PPD dosyasına FoomaticRIPCommandLine parametresi ile kod çalıştırmasına olanak tanır. FoomaticRIPCommandLine parametresinde belirtilen shell komutları, parametre üçüncü taraf bir kaynak tarafından belirlenmiş olsa bile olduğu gibi çalıştırılır. Örneğin, /tmp/VULNERABLE dosyasına yazmak için "FoomaticRIPCommandLine: "echo 1 > /tmp/VULNERABLE" belirtilebilir.
- CVE-2024-47175 — libppd'de, IPP niteliklerinin geçici bir PPD dosyasına yazılması sırasında ppdCreatePPDFromIPP2 değerinin doğrulanmaması nedeniyle bir zafiyet ortaya çıkmaktadır. Bu sorun, satır sonu karakteri kullanarak nitelikleri ekleyerek sonuçta oluşan PPD dosyasına rastgele verilerin yerleştirilmesine olanak tanır. Örneğin, denetimi atlayarak izin verilen niteliklerin yanında FoomaticRIPCommandLine niteliğini de ekleyebilir ve bu şekilde yukarıda bahsedilen cups-filters zafiyetini istismar edebilirsiniz.
- CVE-2024-47076 — cups-filters paketindeki libcupsfilters kütüphanesinde, harici bir IPP sunucusundan dönen cfGetPrinterAttributes5 değerlerinin kontrol edilmemesi ile ilgili bir zafiyet, saldırgana CUPS'ın diğer alt sistemlerinde rastgele IPP niteliklerinin işlenmesini sağlama imkanı verir. Örneğin, PPD dosyalarının oluşturulması sırasında.
CUPS'a yönelik bir saldırı senaryosu şu adımları içermektedir:
- Saldırganın kendi IPP sunucusunu dağıtması.
- Kurbanına, saldırganın IPP sunucusuna bağlı bir yazıcıya işaret eden bir UDP paketi göndermesi.
- Bu paketin alınmasının ardından, kurbanın sistemi saldırganın IPP sunucusuna bağlanarak yazıcı niteliklerini istemektedir.
- Kurbanın isteğine yanıt olarak, saldırganın IPP sunucusu, arasından FoomaticRIPCommandLine niteliğinin de bulunduğu nitelikler ile PPD dosyasını döndürür. Bu nitelik, geçerli niteliklerden birine bağlanarak, tek bir satırda " " karakteri kullanılarak eklenir (örneğin, "cupsPrivacyURI: "https://www.google.com/ *FoomaticRIPCommandLine: "), bu da denetimi aşmaya yardımcı olur ve elde edilen veriler geçici bir dosyaya kaydedilirken FoomaticRIPCommandLine'in ayrı bir nitelik olarak yazılmasına neden olur.
- Gönderilen nitelikler sistemde işlendikten sonra kurbanın sisteminde bir PPD dosyası oluşturulur: … *cupsSNMPSupplies: False *cupsLanguages: "en" *cupsPrivacyURI: "https://www.google.com/" *FoomaticRIPCommandLine: "echo 1 > /tmp/I_AM_VULNERABLE" *cupsFilter2: "application/pdf application/vnd.cups-postscript 0 foomatic-rip" *cupsSingleFile: True *cupsFilter2: "application/vnd.cups-pdf application/pdf 0 -" …
- Yaralananın sistemindəki hücumçunun təsdiq etdiyi printerdə çap etmə zamanı "echo 1 > /tmp/I_AM_VULNERABLE" komandası yerinə yetiriləcək
Zəiflikləri aşkar edən araşdırmaçı, zəifliği tapmaq üçün bir neçə gün vaxt sərf etdiyini, lakin nəticədə OpenPrinting layihəsinin inkişafçıları ilə 22 gün davam edən mübahisəli müzakirələrə başladığını qeyd edir. Onları problemin vacibliyinə və yamanların hazırlanmasına inandırmaq çətin idi. Müzakirələr, göstərilən problemləri düzəltməyi müzakirə etməyə qərar verdikdə çətinləşdi və tənqidçi məsələni açıqlayaraq ictimaiyyətin diqqətini çəkdi. Maraqlıdır ki, məlumat sızması yarandı; burada CERT-ə təqdim edilən gizli hesabat və istismar breachforums.st forumunda açıq şəkildə yayımlandı, baxmayaraq ki, məlumatın açıqlanması qadağan olunmuşdu.
Mənbə: opennet.ru
