tigger.uic.edu
http://tigger.uic.edu/~jlongs2/holes/cups2.txt CVE-2004-1269
Easy Software Products LPPassWd 1.1.22 - Resource Limit Denial of Service
Record summary
CVE-2004-1269 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEasy Software Products LPPassWd 1.1.22 - Resource Limit Denial of ServiceExploitDB exploitby Bartlomiej SiekaNot analyzed1 file
References
9GLSA-200412-25Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml MDKSA-2005:008Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:008 RHSA-2005:013Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-013.html RHSA-2005:053Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-053.html cups-lppasswd-dos(18608)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18608 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1269 oval:org.mitre.oval:def:9545vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9545 USN-50-1Vendor advisory
https://usn.ubuntu.com/50-1