CVE-2004-0923: Low severity Easy Software Products Cups vulnerability
Published Oct 26, 2004
·Updated
CUPS 1.1.20 and earlier records authentication information for a device URI in the errorlog file, which allows local users to obtain user names and passwords.
Affected Software
51 affected components
Easy Software Products Cups=1.1.19_rc5
Easy Software Products Cups=1.1.10
Easy Software Products Cups=1.1.16
Easy Software Products Cups=1.1.7
Easy Software Products Cups=1.0.4_8
Easy Software Products Cups=1.1.15
Easy Software Products Cups=1.1.21
Easy Software Products Cups=1.1.13
Easy Software Products Cups=1.1.17
Easy Software Products Cups=1.1.4_3
Easy Software Products Cups=1.1.4
Easy Software Products Cups=1.1.12
Easy Software Products Cups=1.1.4_5
Easy Software Products Cups=1.1.1
Easy Software Products Cups=1.1.20
Easy Software Products Cups=1.1.18
Easy Software Products Cups=1.1.19
Easy Software Products Cups=1.0.4
Easy Software Products Cups=1.1.14
Easy Software Products Cups=1.1.4_2
Easy Software Products Cups=1.1.6
Apple Mac OS X Server=10.3.2
Apple iOS and macOS=10.2.5
Apple Mac OS X Server=10.2.2
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple Mac OS X Server=10.2.4
Apple iOS and macOS=10.2.1
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.2.3
Apple iOS and macOS=10.2.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.2.2
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.3
Apple Mac OS X Server=10.2.8
Apple iOS and macOS=10.2
Apple iOS and macOS=10.3
Remediation
Patch Available
Patch Available
Event History
Oct 26, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0923?
CVE-2004-0923 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2004-0923?
To fix CVE-2004-0923, update CUPS to version 1.1.21 or later.
3
Who is affected by CVE-2004-0923?
CVE-2004-0923 affects users of CUPS versions 1.1.20 and earlier.
4
What type of vulnerability is CVE-2004-0923?
CVE-2004-0923 is an information disclosure vulnerability.
5
Can local users exploit CVE-2004-0923?
Yes, local users can exploit CVE-2004-0923 to obtain sensitive authentication information.