The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-03-05T19:00:00
Updated: 2024-08-07T00:45:12.192Z
Reserved: 2010-01-27T00:00:00
Link: CVE-2010-0393
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-03-05T19:30:00.470
Modified: 2024-11-21T01:12:07.547
Link: CVE-2010-0393
Redhat