CUPS prior to 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows malicious users to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple cups |
||
apple cups 1.1.21 |
||
canonical ubuntu linux 4.10 |