CVE-2008-5377
CUPS 1.3.8 - Arbitrary File Overwrite via Symlink Attack on Temporary File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5377. PoCs published by Jon Oberheide.
AI-analyzed exploit summary This exploit leverages a symlink attack on the CUPS pstopdf filter to overwrite /etc/ld.so.preload, enabling local privilege escalation by preloading a malicious shared library. It requires specific conditions such as CUPS executing filters as a privileged user and a printer using the pstopdf filter.
Description
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Exploits (1)
This exploit leverages a symlink attack on the CUPS pstopdf filter to overwrite /etc/ld.so.preload, enabling local privilege escalation by preloading a malicious shared library. It requires specific conditions such as CUPS executing filters as a privileged user and a printer using the pstopdf filter.