CVE-2004-1270
published 2005-01-10CVE-2004-1270: lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.45%
36.7th percentile
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| debian | cups | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxq6-gg87-xqc4: lppasswd in CUPS 1
ghsa_unreviewed·2022-04-29
CVE-2004-1270 [LOW] GHSA-hxq6-gg87-xqc4: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
OSV
CVE-2004-1270: lppasswd in CUPS 1
osv·2005-01-10·CVSS 2.1
CVE-2004-1270 [LOW] CVE-2004-1270: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
CAN-2004-1125:
The recent USN-48-1 fixed a buffer overflow in xpdf. Since CUPS
contains xpdf code to convert incoming PDF files to the PostScript
format, this vulnerability applies to cups as well.
In this case it could even lead to privilege escalation: if an
attacker submitted a malicious PDF file for printing, he could be
able to execute arbitrary commands with the privileges of the
CUPS server.
Please note that the Ubuntu version of CUPS runs as a minimally
privileged user 'cupsys' by default, so there is no possibility of
root privilege escalation. The privileges of the 'cupsys' user are
confined to modifying printer configurations, altering print jobs,
and controlling printers.
CAN-2004-1267:
Ariel Berkman discovered a
Red Hat
security flaw
vendor_redhat·2004-12-15·CVSS 2.1
CVE-2004-1270 [LOW] security flaw
security flaw
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Debian
CVE-2004-1270: cups - lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file d...
vendor_debian·2004·CVSS 2.1
CVE-2004-1270 [LOW] CVE-2004-1270: cups - lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file d...
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fixed in 1.1.22-2)
No detection rules found.
No public exploits indexed.
http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507https://usn.ubuntu.com/50-1/http://tigger.uic.edu/~jlongs2/holes/cups2.txthttp://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:008http://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507https://usn.ubuntu.com/50-1/
2005-01-10
Published