Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.
Problem types
CWE-863: Incorrect Authorization
Product status
References
github.com/...g/cups/security/advisories/GHSA-v987-m8hp-phj9
github.com/...ommit/88516bf6d9e34cef7a64a704b856b837f70cd220