Vulnerability Note VU#557062
CUPS stores user account details in plain text in log file
Overview
When an SMB printer is configured, CUPS stores plain text login information to the log file.
Description
CUPS is a cross-platform printing system for UNIX environments. It can use the IPP, LPD, SMB, and JetDirect protocols to interact with printers. The SMB protocol is used to communicate with printers that are shared via Microsoft Windows or other SMB-compatible software such as Samba. When an SMB printer is added or modified, the connection string for the printer is written to the log file in plain text. This connection string will contain a username and password if authentication is required for the printer. |
Impact
A local authenticated user may be able to retrieve the usernames and passwords for other accounts. |
Solution
Apply a patch from your vendor For vendor-specific information regarding vulnerable status and patch availability, please see the Systems Affected section of this document. |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian | Affected | 04 Oct 2004 | 18 Oct 2004 |
| MandrakeSoft | Affected | 04 Oct 2004 | 22 Oct 2004 |
| Hitachi | Not Affected | 04 Oct 2004 | 08 Oct 2004 |
| NETBSD | Not Affected | 04 Oct 2004 | 05 Oct 2004 |
| BSDI | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| Conectiva | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| Cray Inc. | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| EMC Corporation | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| Engarde | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| F5 Networks | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| FreeBSD | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| Fujitsu | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| Hewlett-Packard Company | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| IBM | Unknown | 04 Oct 2004 | 04 Oct 2004 |
| IBM-zSeries | Unknown | 04 Oct 2004 | 04 Oct 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.securitytracker.com/alerts/2004/Oct/1011529.html
- http://secunia.com/advisories/12736/
- http://fedoranews.org/updates/FEDORA-2004-331.shtml
- http://www.cups.org/ssr.html
Credit
Thanks to Gary Smith for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
- CVE IDs: CAN-2004-0923
- Date Public: 05 Oct 2004
- Date First Published: 19 Nov 2004
- Date Last Updated: 17 Dec 2004
- Severity Metric: 5.06
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.