The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
Thu, 22 May 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |

Status: PUBLISHED
Assigner: mitre
Published: 2010-03-05T19:00:00
Updated: 2024-08-07T00:45:12.192Z
Reserved: 2010-01-27T00:00:00
Link: CVE-2010-0393

No data.

Status : Deferred
Published: 2010-03-05T19:30:00.470
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-0393
