VDB

DEBIAN-CVE-2010-0393

DEBIAN-CVE-2010-0393 PUBLISHED

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.

Affected Products

VendorProductVersions
Debian:13cups0, 0, 0
Debian:14cups0, 0, 0
Debian:11cups0, 0, 0
Debian:12cups0, 0, 0

Timeline

  • Mar 5, 2010 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›