vendor:
lppasswd
by:
Bartlomiej Sieka
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: lppasswd
Affected Version From: 1.1.19
Affected Version To: 1.1.22
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: FreeBSD 5.2
2004
Easy Software Products lppasswd Denial of Service Vulnerability
The Easy Software Products lppasswd utility is prone to a locally exploitable denial-of-service vulnerability. The issue occurs when the program attempts to write a file to the system that will exceed any file size resource limits in place. An unprivileged user with CUPS credentials can set these resource limits and then invoke the application, which will create an empty '/usr/local/etc/cups/passwd.new' file. Subsequent invocations of lppasswd will fail if this file is present. Successful exploitation of this vulnerability will prevent users from changing their CUPS passwords with lppasswd.
Mitigation:
There is no known mitigation for this vulnerability. It is recommended to update to a patched version of the software.