lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2004-12-22T05:00:00

Updated: 2024-08-08T00:46:12.304Z

Reserved: 2004-12-20T00:00:00

Link: CVE-2004-1270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-01-10T05:00:00.000

Modified: 2018-10-03T21:29:23.090

Link: CVE-2004-1270

cve-icon Redhat

Severity : Important

Publid Date: 2004-12-15T00:00:00Z

Links: CVE-2004-1270 - Bugzilla