CUPS Case Sensitive Location Directive May Let Remote Users Bypass Access Controls
|
|
SecurityTracker Alert ID: 1014482
|
|
SecurityTracker URL: http://securitytracker.com/id?1014482
|
|
CVE Reference: CAN-2004-2154
(Links to External Site)
|
Date: Jul 14 2005
|
Impact: Host/resource access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.1.21rc1
|
Description: In May 2004, a vulnerability was reported in CUPS. A remote user can bypass access control lists in certain cases.
The printer name in the Location directive in the 'cupsd.conf' configuration file is case sensitive. A remote user can supply a
printer name containing uppercase or lowercase letters that are different from the case specified in the directive to bypass the
directive's access control lists. As a result, a remote or local user can print to a password-protected target queue without having
to supply the password.
'adji.df.uba' reported this vulnerability.
|
Impact: A remote user may be able to bypass Location directive access controls.
|
Solution: The vendor has released a fixed version (1.1.21rc1).
|
Vendor URL: www.cups.org/str.php?L700 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 14 Jul 2005 14:50:54 -0400
Subject: http://www.cups.org/str.php?L700
|
> Summary: Location and printer name case sensitivity
> Fix Version: 1.1.21rc1
> 10:05 May 13, 2004
|
|