PT-2010-5632 · Apple+1 · Cups-Common+13

Tim Waugh

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-0393

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CUPS versions 1.2.2, 1.3.7, 1.3.9, and 1.4.1 libcups2 (affected versions not specified) libcups2-dev (affected versions not specified) libcupsimage2 (affected versions not specified) libcupsimage2-dev (affected versions not specified) libcupsys2 (affected versions not specified) libcupsys2-dev (affected versions not specified) cups-common (affected versions not specified) cups-client (affected versions not specified) cups-bsd (affected versions not specified) cups-dbg (affected versions not specified) cupsys (affected versions not specified) cupsys-client (affected versions not specified) cupsys-common (affected versions not specified) cupsys-bsd (affected versions not specified) cupsys-dbg (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the CUPS package and its related components in the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Recommendations For CUPS versions 1.2.2, 1.3.7, 1.3.9, and 1.4.1: consider disabling the cupsGetlang function until a patch is available. For libcups2, libcups2-dev, libcupsimage2, libcupsimage2-dev, libcupsys2, libcupsys2-dev, cups-common, cups-client, cups-bsd, cups-dbg, cupsys, cupsys-client, cupsys-common, cupsys-bsd, and cupsys-dbg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01427
BDU:2015-01428
BDU:2015-01429
BDU:2015-01430
BDU:2015-01431
BDU:2015-01432
BDU:2015-01433
BDU:2015-01434
BDU:2015-01435
BDU:2015-03343
BDU:2015-03344
BDU:2015-03345
BDU:2015-03346
BDU:2015-03347
BDU:2015-03348
CVE-2010-0393
DSA-2007-1
OPENSUSE-SU-2024:10075-1

Affected Products

Cups
Debian
Cups-Bsd
Cups-Client
Cups-Common
Cups-Dbg
Cupsys
Cupsys-Bsd
Cupsys-Dbg
Libcups2
Libcups2-Dev
Libcupsimage2
Libcupsimage2-Dev
Libcupsys2