Local Privilege Escalation in CUPS by Apple and Other Vendors
CVE-2010-0393
Currently unrated
Summary
The vulnerability arises from the _cupsGetlang function in the lppasswd component of CUPS, which incorrectly relies on an environment variable to determine the source of localized message strings. This flaw permits local users to execute malicious files containing tailored localization data with format string specifiers. As a result, attackers can potentially escalate their privileges within the affected environment, leading to unauthorized access and manipulation.
References
Timeline
Vulnerability published
Vulnerability Reserved