Collected research
Local DoS on CUPS to a remote exploit via specially-crafted webpage
Pwning Ubuntu via CUPS
pagvac uses the browser as a bridge to a localhost-only daemon: cupsd runs as root on default Ubuntu Desktop and listens on 127.0.0.1:631, and a web page writing 101 image tags at its add-rss-subscription endpoint crashes it reliably, with no CUPS authentication on 8.04. Includes the crash PoC, a bash cleanup script, and the argument that root-owned local services are remotely reachable via CSRF.
Record
- Document
- Pwning Ubuntu via CUPS
- Researcher
- Adrian Pastor
- Published by
- gnucitizen.org
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Pastor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .