7.5
CVSSv2

CVE-2004-2154

Published: 31/12/2004 Updated: 15/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CUPS prior to 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows malicious users to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups

apple cups 1.1.21

canonical ubuntu linux 4.10

Vendor Advisories

Synopsis cups security update Type/Severity Security Advisory: Moderate Topic Updated CUPS packages that fix a security issue are now available for RedHat Enterprise Linux 3This update has been rated as having moderate security impact by the Red HatSecurity Response Team Description The C ...
A flaw was detected in the printer access control list checking in the CUPS server Printer names were compared in a case sensitive manner; by modifying the capitalization of printer names, a remote attacker could circumvent ACLs and print to printers he should not have access to ...