CVE-2010-0393
published 2010-03-05CVE-2010-0393: The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.32%
24.3th percentile
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | >= 0 < 1.4.2-9.1 | 1.4.2-9.1 |
| apple | cups | >= 0 < 1.4.2-9.1 | 1.4.2-9.1 |
| apple | cups | >= 0 < 1.4.2-9.1 | 1.4.2-9.1 |
| apple | cups | >= 0 < 1.4.2-9.1 | 1.4.2-9.1 |
| debian | cups | < cups 1.4.2-9.1 (bookworm) | cups 1.4.2-9.1 (bookworm) |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6j26-qg9p-xqqm: The _cupsGetlang function, as used by lppasswd
ghsa_unreviewed·2022-05-02
CVE-2010-0393 [MEDIUM] GHSA-6j26-qg9p-xqqm: The _cupsGetlang function, as used by lppasswd
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
OSV
CVE-2010-0393: The _cupsGetlang function, as used by lppasswd
osv·2010-03-05·CVSS 6.9
CVE-2010-0393 [MEDIUM] CVE-2010-0393: The _cupsGetlang function, as used by lppasswd
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-03-03·CVSS 7.5
CVE-2009-3553 [HIGH] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
It was discovered that the CUPS scheduler did not properly handle certain
network operations. A remote attacker could exploit this flaw and cause the
CUPS server to crash, resulting in a denial of service. This issue only
affected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,
CVE-2010-0302)
Ronald Volgers discovered that the CUPS lppasswd tool could be made to load
localized message strings from arbitrary files by setting an environment
variable. A local attacker could exploit this with a format-string
vulnerability leading to a root privilege escalation. The default compiler
options for Ubuntu 8.10, 9.04 and 9.10 should reduce this vulnerability to
a denial of service. (CVE-2010-0393)
Instructions: In general, a standar
Red Hat
: cups possible arbitrary code execution via suid lppasswd (STR #3482)
vendor_redhat·2010-03-03·CVSS 6.9
CVE-2010-0393 [MEDIUM] : cups possible arbitrary code execution via suid lppasswd (STR #3482)
: cups possible arbitrary code execution via suid lppasswd (STR #3482)
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Statement: This issue did not affected Red Hat Enterprise Linux 3 and 4 due to the lack of localization in lppasswd as provided in those releases.
The affected code is present in Red Hat Enterprise Linux 5, however lppasswd is not shipped setuid so is not vulnerable to this issue. If a user were to enable the setuid bit on lppasswd, the impact would only be a crash of lppasswd due to use of FORTIFY_S
Debian
CVE-2010-0393: cups - The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3....
vendor_debian·2010·CVSS 6.9
CVE-2010-0393 [MEDIUM] CVE-2010-0393: cups - The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3....
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Scope: local
bookworm: resolved (fixed in 1.4.2-9.1)
bullseye: resolved (fixed in 1.4.2-9.1)
forky: resolved (fixed in 1.4.2-9.1)
sid: resolved (fixed in 1.4.2-9.1)
trixie: resolved (fixed in 1.4.2-9.1)
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4077http://www.cups.org/str.php?L3482http://www.mandriva.com/security/advisories?name=MDVSA-2010:072http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.securityfocus.com/bid/38524http://www.ubuntu.com/usn/USN-906-1https://bugzilla.redhat.com/show_bug.cgi?id=558460http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4077http://www.cups.org/str.php?L3482http://www.mandriva.com/security/advisories?name=MDVSA-2010:072http://www.mandriva.com/security/advisories?name=MDVSA-2010:073http://www.securityfocus.com/bid/38524http://www.ubuntu.com/usn/USN-906-1https://bugzilla.redhat.com/show_bug.cgi?id=558460
2010-03-05
Published