CUPS Vulnerability Allows Local File Overwrite in Multiple Versions
CVE-2010-2431

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
22 June 2010

Summary

The cupsFileOpen function in CUPS prior to version 1.4.4 is susceptible to a file overwrite vulnerability. Local users who are members of the lp group can exploit this flaw by leveraging a symlink attack to overwrite arbitrary files. This attack targets the /var/cache/cups/remote.cache or /var/cache/cups/job.cache files, potentially leading to unauthorized access or modification of sensitive data. Organizations using affected versions should apply necessary updates to mitigate risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.