CVE-2010-0393: Medium severity apple CUPS vulnerability
CUPS 1.3.x and earlier ships setuid binaries which use environment variables to set the directories in which they operate.
Other sources
The cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0393?
CVE-2010-0393 has a high severity level due to its potential to allow privilege escalation.
How do I fix CVE-2010-0393?
You can fix CVE-2010-0393 by upgrading to a patched version of CUPS, specifically versions later than 1.4.1.
What versions of CUPS are affected by CVE-2010-0393?
CVE-2010-0393 affects CUPS versions 1.2.2, 1.3.7, 1.3.9, and 1.4.1.
What type of vulnerability is CVE-2010-0393?
CVE-2010-0393 is classified as a privilege escalation vulnerability.
What impact does CVE-2010-0393 have on system security?
The impact of CVE-2010-0393 is significant as it may allow unauthorized users to execute code with elevated privileges on the system.