Security Advisory

CVE-2010-2431

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-06-22 20:24:00
Last updated 2024-08-07 02:32:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.