cups-filters-cups-browsed
OpenPrinting optional cups-browsed for CUPS
cups-browsed auto-discovers printers which are announced via DNS-SD and auto-creates local print queues for them. Normally the cups-browsed.service should not be activated because it is a generic security risk when a service accepts any (possibly malicious) incoming information from any host in the local network (in particular DNS-SD announcements) and from that information it auto-creates print queue configurations for CUPS where the CUPS server program cupsd runs as root. Both cupsd and cups-browsed are network services that are designed for use in a trusted internal network and not intended to be exposed to the public Internet or to other non-trusted networks which means: It is crucial to limit access to cupsd and cups-browsed to trusted users. It is crucial to limit access to network printer devices to trusted users. It is crucial to not accept remote printing information from untrusted hosts. For more information see the openSUSE support database article https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
GPL-2.0-only AND GPL-2.0-or-later AND GPL-3.0-only AND MIT