Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability

Easy Software Products lppasswd is prone to a locally exploitable denial of service vulnerability. This issue occurs when the program attempts to write a file to the system that will exceed any file size resource limits in place. This presents a vulnerability since an unprivileged user with CUPS credentials may set these resource limits and then invoke the application. This will create an empty '/usr/local/etc/cups/passwd.new' file. If this file is present, then future invocations of lppasswd will fail.

Successful exploitation will prevent users from changing their CUPS passwords with lppasswd.







 

Privacy Statement
Copyright 2008, SecurityFocus