Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2154

Опубликовано: 31 дек. 2004
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*
Версия до 1.1.21 (исключая)
cpe:2.3:a:apple:cups:1.1.21:-:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:4.10:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00487
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-178
CWE-178

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 20 лет назад

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

redhat
больше 21 года назад

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

CVSS3: 9.8
debian
больше 20 лет назад

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as cas ...

CVSS3: 9.8
github
больше 3 лет назад

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

EPSS

Процентиль: 64%
0.00487
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-178
CWE-178