The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-03-05T19:00:00

Updated: 2024-08-07T00:45:12.192Z

Reserved: 2010-01-27T00:00:00

Link: CVE-2010-0393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-03-05T19:30:00.470

Modified: 2013-05-15T03:06:12.197

Link: CVE-2010-0393

cve-icon Redhat

Severity : Important

Publid Date: 2010-03-03T00:00:00Z

Links: CVE-2010-0393 - Bugzilla