2.2.4 Ensure CUPS is not installed

Information

The Common UNIX Print System (CUPS) provides the ability to print to both local and network printers. A system running CUPS can also accept print jobs from remote systems and print them to local printers. It also provides a web based remote administration capability.

Rationale:

If the system does not need to print jobs or accept print jobs from other systems, it is recommended that CUPS be removed to reduce the potential attack surface.

Solution

Run one of the following commands to remove cups :

# apt purge cups

Impact:

Removing CUPS will prevent printing from the system, a common task for workstation systems.

See Also

https://workbench.cisecurity.org/files/2873

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: d8cd1ba6866f54774014ee4ef48a5ff729a010825291f5203951e880f55f835d