The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-22T20:24:00

Updated: 2010-11-09T10:00:00

Reserved: 2010-06-22T00:00:00


Link: CVE-2010-2431

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-06-22T20:30:01.757

Modified: 2013-05-15T03:10:22.313


Link: CVE-2010-2431

JSON object: View

cve-icon Redhat Information

No data.

CWE