Vulnerabilities
Vulnerable Software
Apple:  >> Cups  >> 1.4.8  Security Vulnerabilities
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
CVSS Score
1.2
EPSS Score
0.001
Published
2014-01-26
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
CVSS Score
5.1
EPSS Score
0.077
Published
2011-08-19
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
CVSS Score
6.9
EPSS Score
0.0
Published
2009-01-27
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
CVSS Score
2.1
EPSS Score
0.002
Published
2008-06-02


Contact Us

Shodan ® - All rights reserved