CVE-2002-1366Race Condition in Software Products Cups

7 documents7 sources
Severity
6.2MEDIUMNVD
EPSS
0.1%
top 74.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26
Latest updateApr 30

Description

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages3 packages

Debianapple/cups< 1.1.18-1+3
NVDeasy_software_products/cups9 versions+8
NVDapple/mac_os_x10.2, 10.2.2+1

🔴Vulnerability Details

3
GHSA
GHSA-qq4v-v49x-w99c: Common Unix Printing System (CUPS) 12022-04-30
CVEList
CVE-2002-1366: Common Unix Printing System (CUPS) 12004-09-01
OSV
CVE-2002-1366: Common Unix Printing System (CUPS) 12002-12-26

📋Vendor Advisories

2
Red Hat
security flaw2002-12-19
Debian
CVE-2002-1366: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with...2002

💬Community

1
Bugzilla
CVE-2002-1366 security flaw2018-08-16
CVE-2002-1366 — Race Condition | cvebase