CVE-2004-1269
published 2005-01-10CVE-2004-1269: lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
8.95%
94.7th percentile
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| debian | cups | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5xh-vw4x-23mx: lppasswd in CUPS 1
ghsa_unreviewed·2022-04-29
CVE-2004-1269 [MEDIUM] GHSA-v5xh-vw4x-23mx: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
OSV
CVE-2004-1269: lppasswd in CUPS 1
osv·2005-01-10·CVSS 5.0
CVE-2004-1269 [MEDIUM] CVE-2004-1269: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
CAN-2004-1125:
The recent USN-48-1 fixed a buffer overflow in xpdf. Since CUPS
contains xpdf code to convert incoming PDF files to the PostScript
format, this vulnerability applies to cups as well.
In this case it could even lead to privilege escalation: if an
attacker submitted a malicious PDF file for printing, he could be
able to execute arbitrary commands with the privileges of the
CUPS server.
Please note that the Ubuntu version of CUPS runs as a minimally
privileged user 'cupsys' by default, so there is no possibility of
root privilege escalation. The privileges of the 'cupsys' user are
confined to modifying printer configurations, altering print jobs,
and controlling printers.
CAN-2004-1267:
Ariel Berkman discovered a
Red Hat
security flaw
vendor_redhat·2004-12-15·CVSS 5.0
CVE-2004-1269 [MEDIUM] security flaw
security flaw
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Debian
CVE-2004-1269: cups - lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a f...
vendor_debian·2004·CVSS 5.0
CVE-2004-1269 [MEDIUM] CVE-2004-1269: cups - lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a f...
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fixed in 1.1.22-2)
No detection rules found.
http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18608https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9545https://usn.ubuntu.com/50-1/http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18608https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9545https://usn.ubuntu.com/50-1/
2005-01-10
Published