CVE-2010-2431: Low severity cups vulnerability

Published Jun 17, 2010
·
Updated

Quoting from the upstream bug report http://cups.org/str.php?L3510:

directory that is writable by unprivileged processes.

This is a latent privilege escalation vulnerability. It can be exploited only in the presence of other CUPS vulnerabilities.

Why this is privilege escalation --------------------------------

This is privilege escalation, because an unprivileged process can trick the CUPS server into overwriting arbitrary files as root.

Example:

drwxrwxr-x 4 root lp /var/cache/cups -rw-r----- 1 root lp /var/cache/cups/remote.cache

This file is opened with cupsFileOpen() which simply opens the file with open(filename, OWRONLY | OTRUNC | OCREAT | OLARGEFILE | OBINARY, 0666).

If a CUPS "external" program has a vulnerability, an attacker can use the group=lp privileges to replace /var/cache/cups/remote.cache with a symlink to a root-writable file. CUPS will then overwrite that file as root. A similar latent vulnerability exists for the state file /var/cache/cups/job.cache.

Why this is a latent vulnerability ----------------------------------

This is a latent vulnerability, because there is no known exploit for CUPS "external" programs that run as user=lp, group=lp.

The upstream fix looks more like a preventative fix as there does not seem to be anything exploitable here, so this looks like more a hardening than a response to an actual flaw.

Other sources

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.

MITRE

Affected Software

84 affected components
apple CUPS<=1.4.3
apple CUPS=1.1
apple CUPS=1.1.1
apple CUPS=1.1.2
apple CUPS=1.1.3
apple CUPS=1.1.4
apple CUPS=1.1.5
apple CUPS=1.1.5-1
apple CUPS=1.1.5-2
apple CUPS=1.1.6
apple CUPS=1.1.6-1
apple CUPS=1.1.6-2
apple CUPS=1.1.6-3
apple CUPS=1.1.7
apple CUPS=1.1.8
apple CUPS=1.1.9
apple CUPS=1.1.9-1
apple CUPS=1.1.10
apple CUPS=1.1.10-1
apple CUPS=1.1.11
apple CUPS=1.1.12
apple CUPS=1.1.13
apple CUPS=1.1.14
apple CUPS=1.1.15
apple CUPS=1.1.16
apple CUPS=1.1.17
apple CUPS=1.1.18
apple CUPS=1.1.19
apple CUPS=1.1.19-rc1
apple CUPS=1.1.19-rc2
apple CUPS=1.1.19-rc3
apple CUPS=1.1.19-rc4
apple CUPS=1.1.19-rc5
apple CUPS=1.1.20
apple CUPS=1.1.20-rc1
apple CUPS=1.1.20-rc2
apple CUPS=1.1.20-rc3
apple CUPS=1.1.20-rc4
apple CUPS=1.1.20-rc5
apple CUPS=1.1.20-rc6
apple CUPS=1.1.21
apple CUPS=1.1.21-rc1
apple CUPS=1.1.21-rc2
apple CUPS=1.1.22
apple CUPS=1.1.22-rc1
apple CUPS=1.1.22-rc2
apple CUPS=1.1.23
apple CUPS=1.1.23-rc1
apple CUPS=1.2-b1
apple CUPS=1.2-b2
apple CUPS=1.2-rc1
apple CUPS=1.2-rc2
apple CUPS=1.2-rc3
apple CUPS=1.2.0
apple CUPS=1.2.1
apple CUPS=1.2.2
apple CUPS=1.2.3
apple CUPS=1.2.4
apple CUPS=1.2.5
apple CUPS=1.2.6
apple CUPS=1.2.7
apple CUPS=1.2.8
apple CUPS=1.2.9
apple CUPS=1.2.10
apple CUPS=1.2.11
apple CUPS=1.2.12
apple CUPS=1.3-b1
apple CUPS=1.3-rc1
apple CUPS=1.3-rc2
apple CUPS=1.3.0
apple CUPS=1.3.1
apple CUPS=1.3.2
apple CUPS=1.3.3
apple CUPS=1.3.4
apple CUPS=1.3.5
apple CUPS=1.3.6
apple CUPS=1.3.7
apple CUPS=1.3.8
apple CUPS=1.3.9
apple CUPS=1.3.10
apple CUPS=1.3.11
apple CUPS=1.4.0
apple CUPS=1.4.1
apple CUPS=1.4.2

Remediation

Event History

Jun 17, 2010
Data Sourced
08:27 PM
DescriptionSeverityAffected Software
Jun 22, 2010
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2010-2431?

CVE-2010-2431 is classified as a latent privilege escalation vulnerability.

2

How can CVE-2010-2431 be exploited?

CVE-2010-2431 can only be exploited in conjunction with other vulnerabilities in CUPS.

3

What versions of CUPS are affected by CVE-2010-2431?

CVE-2010-2431 affects various versions of Apple CUPS up to 1.4.3.

4

What measures can be taken to mitigate CVE-2010-2431?

To mitigate CVE-2010-2431, ensure you upgrade to a patched version of CUPS above 1.4.3.

5

Is CVE-2010-2431 still a concern for current systems?

CVE-2010-2431 may still pose a risk if associated vulnerabilities are present in older systems running vulnerable CUPS versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203