The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/42713 | vdb entry |
http://www.securityfocus.com/bid/29484 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-150A.html | third party advisory us government resource |
http://securitytracker.com/id?1020145 | vdb entry |
http://secunia.com/advisories/30430 | third party advisory vendor advisory |
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html | vendor advisory |
http://www.vupen.com/english/advisories/2008/1697 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/29412 | vdb entry |