6.9
CVSSv2

CVE-2010-0393

Published: 05/03/2010 Updated: 15/05/2013
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.2.2

apple cups 1.4.1

apple cups 1.3.7

apple cups 1.3.9

Vendor Advisories

Debian Bug report logs - #572940 CVE-2010-0302: Incomplete security fix Package: cups; Maintainer for cups is Debian Printing Team <debian-printing@listsdebianorg>; Source for cups is src:cups (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 7 Mar 2010 19:00:01 UTC Severity: impor ...
It was discovered that the CUPS scheduler did not properly handle certain network operations A remote attacker could exploit this flaw and cause the CUPS server to crash, resulting in a denial of service This issue only affected Ubuntu 804 LTS, 810, 904 and 910 (CVE-2009-3553, CVE-2010-0302) ...
Ronald Volgers discovered that the lppasswd component of the cups suite, the Common UNIX Printing System, is vulnerable to format string attacks due to insecure use of the LOCALEDIR environment variable An attacker can abuse this behaviour to execute arbitrary code via crafted localization files and triggering calls to _cupsLangprintf() This work ...