The first problem is not a problem either in Debian's potato (2.2) or woody (unstable). Our cupsys packages are shipped with browsing turned off by default.
The second problem has to do with CUPS's configuration. CUPS does access control in a similar way to Apache, and is configured by default in a similar way to Apache. This isn't terribly appropriate in the case of allowing people to attach to printers. Administrative tasks still aren't allowed, but Internet users could (for example) run all the paper out of your printer. Debian as shipped in potato and woody is vulnerable to this latter problem.
The fix is simply to configure access control to reflect your real wishes, which is done in /etc/cups/cupsd.conf. This can be done with the current packages (in both potato and woody).
This has been fixed in version 1.0.4-8 (or 1.1.4-2 for unstable) and we recommend that you upgrade your cupsys packages immediately.