PT-2004-2198 · Apple+1 · Cups+1
Bartlomiej Sieka
·
Published
2004-12-22
·
Updated
2018-10-03
·
CVE-2004-1269
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
CUPS version 1.1.22
Description:
The issue is related to the lppasswd utility in CUPS, which fails to remove the passwd.new file if it encounters a file-size resource limit while writing to it. This causes subsequent invocations of lppasswd to fail.
Recommendations:
For CUPS version 1.1.22, consider manually removing the passwd.new file after an invocation failure to allow subsequent lppasswd invocations to proceed. As a temporary workaround, ensure that sufficient file-size resources are available to prevent such failures.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cups
Red Hat