Local Privilege Escalation in CUPS by Apple and Other Vendors
CVE-2010-0393

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
5 March 2010

Summary

The vulnerability arises from the _cupsGetlang function in the lppasswd component of CUPS, which incorrectly relies on an environment variable to determine the source of localized message strings. This flaw permits local users to execute malicious files containing tailored localization data with format string specifiers. As a result, attackers can potentially escalate their privileges within the affected environment, leading to unauthorized access and manipulation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.