Secunia Logo
 
CVE Reference: CVE-2004-2154
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-2154

Description:
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-185-1

SUSE
  http://www.novell.com/linux/security/advisories/2005_18_sr.html

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-571.html

FEDORA

CONFIRM
  http://www.cups.org/str.php?L700


Return to the previous page.