|
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
Easy Software Products lppasswd is prone to a locally exploitable denial of service vulnerability. This issue occurs when the program attempts to write a file to the system that will exceed any file size resource limits in place. This presents a vulnerability since an unprivileged user with CUPS credentials may set these resource limits and then invoke the application. This will create an empty '/usr/local/etc/cups/passwd.new' file. If this file is present, then future invocations of lppasswd will fail. Successful exploitation will prevent users from changing their CUPS passwords with lppasswd. |
|
|
Privacy Statement |