CVE-2004-1270
EPSS 0.45%
描述
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
如何修補 CVE-2004-1270
要修補 CVE-2004-1270,請將受影響套件升級到下列已修補版本。
- Debian/cups—升級至 1.1.22-2 或更新版本
CVE-2004-1270 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.1.22-2