Vulnerability Description
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Cups | < 1.1.21 |
| Canonical | Ubuntu Linux | 4.10 |
Related Weaknesses (CWE)
References
- http://www.cups.org/str.php?L700Broken LinkPatch
- http://www.novell.com/linux/security/advisories/2005_18_sr.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-571.htmlBroken Link
- http://www.ubuntu.com/usn/usn-185-1Third Party Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
- http://www.cups.org/str.php?L700Broken LinkPatch
- http://www.novell.com/linux/security/advisories/2005_18_sr.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-571.htmlBroken Link
- http://www.ubuntu.com/usn/usn-185-1Third Party Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
FAQ
What is CVE-2004-2154?
CVE-2004-2154 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are ...
How severe is CVE-2004-2154?
CVE-2004-2154 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2004-2154?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Cups, Canonical Ubuntu Linux.