CVE-2004-1268
published 2005-01-10CVE-2004-1268: lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.45%
36.7th percentile
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| debian | cups | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rhq-w6x9-x4gf: lppasswd in CUPS 1
ghsa_unreviewed·2022-04-29
CVE-2004-1268 [LOW] GHSA-7rhq-w6x9-x4gf: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
OSV
CVE-2004-1268: lppasswd in CUPS 1
osv·2005-01-10·CVSS 2.1
CVE-2004-1268 [LOW] CVE-2004-1268: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
CAN-2004-1125:
The recent USN-48-1 fixed a buffer overflow in xpdf. Since CUPS
contains xpdf code to convert incoming PDF files to the PostScript
format, this vulnerability applies to cups as well.
In this case it could even lead to privilege escalation: if an
attacker submitted a malicious PDF file for printing, he could be
able to execute arbitrary commands with the privileges of the
CUPS server.
Please note that the Ubuntu version of CUPS runs as a minimally
privileged user 'cupsys' by default, so there is no possibility of
root privilege escalation. The privileges of the 'cupsys' user are
confined to modifying printer configurations, altering print jobs,
and controlling printers.
CAN-2004-1267:
Ariel Berkman discovered a
Red Hat
security flaw
vendor_redhat·2004-12-15·CVSS 2.1
CVE-2004-1268 [LOW] security flaw
security flaw
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
Debian
CVE-2004-1268: cups - lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file...
vendor_debian·2004·CVSS 2.1
CVE-2004-1268 [LOW] CVE-2004-1268: cups - lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file...
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fixed in 1.1.22-2)
No detection rules found.
No public exploits indexed.
http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10398https://usn.ubuntu.com/50-1/http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10398https://usn.ubuntu.com/50-1/
2005-01-10
Published