CVE-2008-1033
published 2008-06-02CVE-2008-1033: The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain…
PriorityP411low2.1CVSS 2.0
AVNACHAuSCPINAN
EPSS
1.55%
72.4th percentile
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.7-1 | 1.3.7-1 |
| apple | cups | >= 0 < 1.3.7-1 | 1.3.7-1 |
| apple | cups | >= 0 < 1.3.7-1 | 1.3.7-1 |
| apple | cups | >= 0 < 1.3.7-1 | 1.3.7-1 |
| debian | cups | < cups 1.3.7-1 (bookworm) | cups 1.3.7-1 (bookworm) |
CVSS provenance
nvdv2.02.1LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjfh-xcvw-r3vp: The scheduler in CUPS in Apple Mac OS X 10
ghsa_unreviewed·2022-05-01
CVE-2008-1033 [LOW] GHSA-mjfh-xcvw-r3vp: The scheduler in CUPS in Apple Mac OS X 10
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
OSV
CVE-2008-1033: The scheduler in CUPS in Apple Mac OS X 10
osv·2008-06-02·CVSS 2.1
CVE-2008-1033 [LOW] CVE-2008-1033: The scheduler in CUPS in Apple Mac OS X 10
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Red Hat
cups: password disclosure via debug log
vendor_redhat·2008-05-28·CVSS 2.1
CVE-2008-1033 [LOW] cups: password disclosure via debug log
cups: password disclosure via debug log
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Statement: Not vulnerable. This issue did not affect the versions of cups as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Debian
CVE-2008-1033: cups - The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging i...
vendor_debian·2008·CVSS 2.1
CVE-2008-1033 [LOW] CVE-2008-1033: cups - The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging i...
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Scope: local
bookworm: resolved (fixed in 1.3.7-1)
bullseye: resolved (fixed in 1.3.7-1)
forky: resolved (fixed in 1.3.7-1)
sid: resolved (fixed in 1.3.7-1)
trixie: resolved (fixed in 1.3.7-1)
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://secunia.com/advisories/30430http://securitytracker.com/id?1020145http://www.securityfocus.com/bid/29412http://www.securityfocus.com/bid/29484http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697https://exchange.xforce.ibmcloud.com/vulnerabilities/42713http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://secunia.com/advisories/30430http://securitytracker.com/id?1020145http://www.securityfocus.com/bid/29412http://www.securityfocus.com/bid/29484http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697https://exchange.xforce.ibmcloud.com/vulnerabilities/42713
2008-06-02
Published