First published: Mon Jun 02 2008(Updated: )
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Apple macOS Server | =10.5 | |
Apple macOS Server | =10.5.1 | |
Apple macOS Server | =10.5.2 | |
CUPS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1033 is considered a moderate severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2008-1033, disable debug logging in CUPS when using password-protected printers.
CVE-2008-1033 affects Apple Mac OS X 10.5 versions prior to 10.5.3 with CUPS enabled.
CVE-2008-1033 allows attackers to access sensitive credentials stored in authentication environment variables in log data.
CVE-2008-1033 is resolved in Apple Mac OS X 10.5.3 and later, making it less of a concern with updated systems.