Assuming that most routers are silently compromised, with their command-and-control operators just waiting for an exploit like this one, is almost par for the course these days!
The rest of us are thinking in terms of larger networks (in my case with hundreds of subnets and tens of thousands of nodes) where "631 is blocked at the firewall" isn't of much relief. The firewall is merely one, rather easy to get past, barrier. We're also concerned with east/west traffic.
There is no detail in the article about the other.
Sent from my Ubuntu laptop.
[edit: I was wrong, it listens on 0.0.0.0 for UDP. I was only checking TCP. ]
I'm not sure why it deviates from Debian and Ubuntu which its based on though
But it looks like cups-browsed is only needed on the Internet; locally you only need mDNS.
A modern setup doesn't need it and doesn't use it.
Isn't listening on 0.0.0.0 instead of localhost only needed if the machine itself is hosting a printer that needs to be accessible to other hosts?
EDIT: Here's a description of the protocol in question: https://opensource.apple.com/source/cups/cups-327/cups/doc/h...