The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: mitre
Published: 2010-03-05T19:00:00
Updated: 2024-08-07T00:45:12.192Z
Reserved: 2010-01-27T00:00:00
Link: CVE-2010-0393
No data.
Status : Deferred
Published: 2010-03-05T19:30:00.470
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-0393