Upstream information
Description
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.NVD CVSS v2 Base Score: 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 574336 SUSE Security Advisories:- SUSE-SR:2010:007, published Tue, 30 Mar 2010 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise 11 Moblin 2.1 DEBUGINFO |
| SAT Patch Nr: 2149 |
| SUSE Linux Enterprise 11 Moblin 2.1 |
| SAT Patch Nr: 2149 |
| SUSE Linux Enterprise 11 GA DEBUGINFO |
| sle11-debuginfo.ppc sled11.x86 sles11.x86-64 sle11-sdk.x86 sle11-sdk.ppc sles11.ppc sle11-sdk.s390x sles11.x86 sle11-debuginfo.s390x sle11-debuginfo.ia64 sles11.ia64 sle11-sdk.x86-64 sle11-debuginfo.x86-64 sles11.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sled11.x86-64 SAT Patch Nr: 2108 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-debuginfo.ppc sled11.x86 sles11.x86-64 sle11-sdk.x86 sle11-sdk.ppc sles11.ppc sle11-sdk.s390x sles11.x86 sle11-debuginfo.s390x sle11-debuginfo.ia64 sles11.ia64 sle11-sdk.x86-64 sle11-debuginfo.x86-64 sles11.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sled11.x86-64 SAT Patch Nr: 2108 |
| SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 GA |
| sle11-debuginfo.ppc sled11.x86 sles11.x86-64 sle11-sdk.x86 sle11-sdk.ppc sles11.ppc sle11-sdk.s390x sles11.x86 sle11-debuginfo.s390x sle11-debuginfo.ia64 sles11.ia64 sle11-sdk.x86-64 sle11-debuginfo.x86-64 sles11.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sled11.x86-64 SAT Patch Nr: 2108 |
| SUSE Linux Enterprise Server 11 GA |
| sle11-debuginfo.ppc sled11.x86 sles11.x86-64 sle11-sdk.x86 sle11-sdk.ppc sles11.ppc sle11-sdk.s390x sles11.x86 sle11-debuginfo.s390x sle11-debuginfo.ia64 sles11.ia64 sle11-sdk.x86-64 sle11-debuginfo.x86-64 sles11.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sled11.x86-64 SAT Patch Nr: 2108 |
| SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 GA |
| sle11-debuginfo.ppc sled11.x86 sles11.x86-64 sle11-sdk.x86 sle11-sdk.ppc sles11.ppc sle11-sdk.s390x sles11.x86 sle11-debuginfo.s390x sle11-debuginfo.ia64 sles11.ia64 sle11-sdk.x86-64 sle11-debuginfo.x86-64 sles11.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sled11.x86-64 SAT Patch Nr: 2108 |
| SUSE Linux Enterprise 11 Moblin 2.1 DEBUGINFO |
| SAT Patch Nr: 2324 |
| SUSE Linux Enterprise 11 Moblin 2.1 |
| SAT Patch Nr: 2324 |
| SUSE Linux Enterprise 11 Moblin 2.0 |
| SAT Patch Nr: 2323 |
| SUSE Linux Enterprise 11 Moblin 2.0 |
| SAT Patch Nr: 2323 |
| SUSE Linux Enterprise 11 Moblin 2.0 |
| SAT Patch Nr: 2105 |
| SUSE Linux Enterprise 11 Moblin 2.0 |
| SAT Patch Nr: 2105 |
| openSUSE 11.0 |
| |
| openSUSE 11.0 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
|
