CVE-2010-2431

EUVD-2010-2440
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
applecups
𝑥
≤ 1.4.3
applecups
1.1
applecups
1.1.1
applecups
1.1.2
applecups
1.1.3
applecups
1.1.4
applecups
1.1.5
applecups
1.1.5-1
applecups
1.1.5-2
applecups
1.1.6
applecups
1.1.6-1
applecups
1.1.6-2
applecups
1.1.6-3
applecups
1.1.7
applecups
1.1.8
applecups
1.1.9
applecups
1.1.9-1
applecups
1.1.10
applecups
1.1.10-1
applecups
1.1.11
applecups
1.1.12
applecups
1.1.13
applecups
1.1.14
applecups
1.1.15
applecups
1.1.16
applecups
1.1.17
applecups
1.1.18
applecups
1.1.19
applecups
1.1.19:rc1
applecups
1.1.19:rc2
applecups
1.1.19:rc3
applecups
1.1.19:rc4
applecups
1.1.19:rc5
applecups
1.1.20
applecups
1.1.20:rc1
applecups
1.1.20:rc2
applecups
1.1.20:rc3
applecups
1.1.20:rc4
applecups
1.1.20:rc5
applecups
1.1.20:rc6
applecups
1.1.21
applecups
1.1.21:rc1
applecups
1.1.21:rc2
applecups
1.1.22
applecups
1.1.22:rc1
applecups
1.1.22:rc2
applecups
1.1.23
applecups
1.1.23:rc1
applecups
1.2:b1
applecups
1.2:b2
applecups
1.2:rc1
applecups
1.2:rc2
applecups
1.2:rc3
applecups
1.2.0
applecups
1.2.1
applecups
1.2.2
applecups
1.2.3
applecups
1.2.4
applecups
1.2.5
applecups
1.2.6
applecups
1.2.7
applecups
1.2.8
applecups
1.2.9
applecups
1.2.10
applecups
1.2.11
applecups
1.2.12
applecups
1.3:b1
applecups
1.3:rc1
applecups
1.3:rc2
applecups
1.3.0
applecups
1.3.1
applecups
1.3.2
applecups
1.3.3
applecups
1.3.4
applecups
1.3.5
applecups
1.3.6
applecups
1.3.7
applecups
1.3.8
applecups
1.3.9
applecups
1.3.10
applecups
1.3.11
applecups
1.4.0
applecups
1.4.1
applecups
1.4.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bookworm
2.4.2-3+deb12u7
fixed
bookworm (security)
2.4.2-3+deb12u8
fixed
bullseye
2.3.3op2-3+deb11u8
fixed
bullseye (security)
2.3.3op2-3+deb11u9
fixed
sid
2.4.10-2
fixed
trixie
2.4.10-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
dapper
dne
hardy
dne
jaunty
Fixed 1.3.9-17ubuntu3.9
released
karmic
Fixed 1.4.1-5ubuntu2.6
released
lucid
Fixed 1.4.3-1ubuntu1.2
released
cupsys
dapper
Fixed 1.2.2-0ubuntu0.6.06.19
released
hardy
Fixed 1.3.7-1ubuntu3.11
released
jaunty
dne
karmic
dne
lucid
dne