CVE-2010-2431
published 2010-06-22CVE-2010-2431: The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1)…
PriorityP47low2.6CVSS 2.0
AVLACHAuNCNIPAP
EPSS
0.36%
28.2th percentile
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.3 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:N/I:P/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups: latent privilege escalation vulnerability
vendor_redhat·2010-06-15·CVSS 2.6
CVE-2010-2431 [LOW] cups: latent privilege escalation vulnerability
cups: latent privilege escalation vulnerability
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
Statement: This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3 or 4. It was addressed in Red Hat Enterprise Linux 5 via RHSA-2010:0811.
Package: cups (Red Hat Enterprise Linux 4) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2010-2431: cups - The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group...
vendor_debian·2010·CVSS 2.6
CVE-2010-2431 [LOW] CVE-2010-2431: cups - The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group...
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
GHSA
GHSA-q362-8vfv-xw4c: The cupsFileOpen function in CUPS before 1
ghsa_unreviewed·2022-05-17
CVE-2010-2431 [LOW] CWE-59 GHSA-q362-8vfv-xw4c: The cupsFileOpen function in CUPS before 1
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
OSV
CVE-2010-2431: The cupsFileOpen function in CUPS before 1
osv·2010-06-22·CVSS 2.6
CVE-2010-2431 [LOW] CVE-2010-2431: The cupsFileOpen function in CUPS before 1
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
No detection rules found.
Bugzilla
CVE-2010-2431 cups: latent privilege escalation vulnerability
bugzilla·2010-06-17·CVSS 2.6
CVE-2010-2431 [LOW] CVE-2010-2431 cups: latent privilege escalation vulnerability
CVE-2010-2431 cups: latent privilege escalation vulnerability
Quoting from the upstream bug report http://cups.org/str.php?L3510:
directory that is writable by unprivileged processes.
This is a latent privilege escalation vulnerability. It can be
exploited only in the presence of other CUPS vulnerabilities.
Why this is privilege escalation
This is privilege escalation, because an unprivileged process can
trick the CUPS server into overwriting arbitrary files as root.
Example:
drwxrwxr-x 4 root lp /var/cache/cups
-rw-r----- 1 root lp /var/cache/cups/remote.cache
This file is opened with cupsFileOpen() which simply opens the file
with open(filename, O_WRONLY | O_TRUNC | O_CREAT | O_LARGEFILE |
O_BINARY, 0666).
If a CUPS "external" program has a vulnerability, an attacker can
use the
Bugzilla
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
bugzilla·2010-06-17·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=591983
Please note: this issue af
http://cups.org/articles.php?L596http://cups.org/str.php?L3510http://rhn.redhat.com/errata/RHSA-2010-0811.htmlhttp://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.vupen.com/english/advisories/2010/2856http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=605397http://cups.org/articles.php?L596http://cups.org/str.php?L3510http://rhn.redhat.com/errata/RHSA-2010-0811.htmlhttp://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.vupen.com/english/advisories/2010/2856http://www.vupen.com/english/advisories/2011/0535https://bugzilla.redhat.com/show_bug.cgi?id=605397
2010-06-22
Published