Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CUPS Insecure Temporary File Creation Vulnerability

It has been reported that some versions of CUPS may create temporary files in an insecure manner.

The vulnerability occurs when creating the '/etc/cups/certs/<pid>' file. An attacker can exploit this vulnerability to create or overwrite any file with elevated privileges.

Successful exploitation is time dependent and require the attacker to obtain the 'lp' user privileges.







 

Privacy Statement
Copyright 2008, SecurityFocus