CVE-2004-0927: Medium severity Easy Software Products Cups vulnerability
Published Oct 28, 2004
·Updated
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
Affected Software
51 affected components
Easy Software Products Cups=1.1.19_rc5
Easy Software Products Cups=1.1.10
Easy Software Products Cups=1.1.16
Easy Software Products Cups=1.1.7
Easy Software Products Cups=1.0.4_8
Easy Software Products Cups=1.1.15
Easy Software Products Cups=1.1.21
Easy Software Products Cups=1.1.13
Easy Software Products Cups=1.1.17
Easy Software Products Cups=1.1.4_3
Easy Software Products Cups=1.1.4
Easy Software Products Cups=1.1.12
Easy Software Products Cups=1.1.4_5
Easy Software Products Cups=1.1.1
Easy Software Products Cups=1.1.20
Easy Software Products Cups=1.1.18
Easy Software Products Cups=1.1.19
Easy Software Products Cups=1.0.4
Easy Software Products Cups=1.1.14
Easy Software Products Cups=1.1.4_2
Easy Software Products Cups=1.1.6
Apple Mac OS X Server=10.3.2
Apple iOS and macOS=10.2.5
Apple Mac OS X Server=10.2.2
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple Mac OS X Server=10.2.4
Apple iOS and macOS=10.2.1
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.2.3
Apple iOS and macOS=10.2.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.2.2
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.3
Apple Mac OS X Server=10.2.8
Apple iOS and macOS=10.2
Apple iOS and macOS=10.3
Remediation
Event History
Oct 28, 2004
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0927?
CVE-2004-0927 is considered to have a moderate severity due to the potential for session decryption by remote attackers.
2
How do I fix CVE-2004-0927?
To fix CVE-2004-0927, update to a later version of Mac OS X or the CUPS software that does not use the same self-signed certificate.
3
Which versions of software are affected by CVE-2004-0927?
CVE-2004-0927 affects various versions of CUPS from 1.0.4 to 1.1.21 and Mac OS X versions from 10.2.8 to 10.3.5.
4
What type of vulnerability is CVE-2004-0927?
CVE-2004-0927 is a cryptographic flaw that allows attackers to decrypt data transmitted during printing sessions.
5
Is CVE-2004-0927 specific to any operating system?
Yes, CVE-2004-0927 specifically impacts Mac OS X 10.2.8 through 10.3.5 installations where CUPS is used.