CVE-2004-1270: Low severity Easy Software Products Cups vulnerability
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1270?
CVE-2004-1270 has been classified with a moderate severity due to its potential impact on local users.
How do I fix CVE-2004-1270?
To mitigate CVE-2004-1270, ensure that file descriptors 0, 1, and 2 are correctly managed when running lppasswd.
What systems are affected by CVE-2004-1270?
CVE-2004-1270 affects various versions of CUPS, specifically from 1.0.4 to 1.1.22.
Can CVE-2004-1270 be exploited remotely?
CVE-2004-1270 is considered a local vulnerability, meaning it requires local user access for exploitation.
Is there a patch available for CVE-2004-1270?
Yes, users should update to a fixed version of CUPS beyond 1.1.22 to eliminate the vulnerability.