PT-2004-3049 · Apple+1 · Cups+1

Publicado

2004-12-31

·

Atualizado

2024-08-01

·

CVE-2004-2154

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.1.21rc1
Description The issue allows attackers to bypass intended Access Control Lists (ACLs) due to the case-sensitive treatment of a Location directive in cupsd.conf. This can be exploited via a printer name containing uppercase or lowercase letters that differ from what is specified in the directive.
Recommendations For versions prior to 1.1.21rc1, update to version 1.1.21rc1 or later to resolve the issue. As a temporary workaround, consider ensuring that all printer names and Location directives in cupsd.conf are specified with consistent case to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2154
RHSA-2005:571
RHSA-2005_571

Produtos afetados

Cups
Red Hat