OPNsense Forum

English Forums => 24.7, 24.10 Legacy Series => Topic started by: adk20 on September 28, 2024, 11:25:44 AM

Title: CUPS vulnerability
Post by: adk20 on September 28, 2024, 11:25:44 AM
I did my homework before asking. No CUPS package to be found in OPNsense and no port 631 listening.

However, since *BSD is potentially affected, I would like to confirm that there is indeed no risk for OPNsense. Could any third-party package install CUPS?

Thank you.
Title: Re: CUPS vulnerability
Post by: bimbar on September 28, 2024, 11:28:58 AM
You can probably install cups if you want to, but I don't see why you would.
Title: Re: CUPS vulnerability
Post by: meyergru on September 28, 2024, 12:02:50 PM
For the packages in the OpnSense repository, Deciso will bring updates if/when that is needed.
Once you enable other repos (inlcuding the official FreeBSD ones), YMMV.

I think there are bigger potential risks than to deliberately install a package on a firewall that does not belong there, like using a package and missing vital points, such as: "When I install squid and enable it for any interface (possibly because I want to filter traffic), it is able to access any other VLAN despite firewall rules saying some VLANs are restricted."