CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://www.novell.com/linux/security/advisories/2005_18_sr.html | vendor advisory broken link |
http://www.cups.org/str.php?L700 | patch broken link |
http://www.redhat.com/support/errata/RHSA-2005-571.html | vendor advisory broken link |
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274 | vendor advisory issue tracking |
http://www.ubuntu.com/usn/usn-185-1 | third party advisory vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9940 | signature vdb entry broken link |
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405 | vendor advisory issue tracking |