CVE-2004-1270
Estado: ModificadaBaja (2.1)—
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://tigger.uic.edu/~jlongs2/holes/cups2.txt
- http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:008
- http://www.redhat.com/support/errata/RHSA-2005-013.html
- http://www.redhat.com/support/errata/RHSA-2005-053.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18609
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507
- https://usn.ubuntu.com/50-1/
- http://tigger.uic.edu/~jlongs2/holes/cups2.txt
- http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:008
- http://www.redhat.com/support/errata/RHSA-2005-013.html
- http://www.redhat.com/support/errata/RHSA-2005-053.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18609
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507
- https://usn.ubuntu.com/50-1/
JSON original (NVD)
Mostrar
{
"id": "CVE-2004-1270",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-01-10T05:00:00.000",
"references": [
{
"url": "http://tigger.uic.edu/~jlongs2/holes/cups2.txt",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:008",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2005-013.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2005-053.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18609",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507",
"source": "cve@mitre.org"
},
{
"url": "https://usn.ubuntu.com/50-1/",
"source": "cve@mitre.org"
},
{
"url": "http://tigger.uic.edu/~jlongs2/holes/cups2.txt",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:008",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2005-013.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2005-053.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18609",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11507",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://usn.ubuntu.com/50-1/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message."
}
],
"lastModified": "2026-06-16T22:07:22.267",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68BD578F-CCAD-4515-9205-EB4F297C6DB4"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.0.4_8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3182CA2-7375-43BC-A0E5-DE11D4B65EE3"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCF4C8D0-3030-4DD5-800B-76A582A4CD0C"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "734D0C2C-F71F-461A-87EE-202C6B706753"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.4_2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F0F402D-5CD0-4477-8B59-C753CECB02BD"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.4_3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "959F7AFA-ED20-434C-993F-06C2A8574662"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.4_5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4F5A0A4-2884-46CA-A846-8B954EB80CFA"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1741CC9D-C4A8-48F9-86CF-EC20AE2A6BE7"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35E65857-12C7-49DE-AD27-3CACD456231C"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47CEF035-57A6-470B-916A-E5562C28E866"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E26BB15-4CF8-4496-A7F7-EB34C444EF72"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D414984E-4F6B-4278-8346-968587E4B18E"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C36DCB-2FDD-44E6-85E8-875575AAE69E"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C4B7C23-0C54-4FBA-A774-9CC1E148376E"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FA0EF14-33E6-4D44-B86E-F04014EA3C8F"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5428EE6-F90A-4BB6-9D8C-8B99E80AB6DF"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A786A770-919E-4E23-949D-D836F316618A"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00A2249C-73DE-434E-A41F-4EDB0ADC0845"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.19_rc5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73AB4D3D-FF35-4A50-A144-3AD41F6F2E55"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB7653F1-70E2-423F-A6A9-30333644B506"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2406EA53-15E7-4CFE-850B-D3CF3FA8560A"
},
{
"criteria": "cpe:2.3:a:easy_software_products:cups:1.1.22_rc1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "787B918D-9CCC-44FE-92AF-E8DF1E91A3C7"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:fedora_core:core_2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6996B14-925B-46B8-982F-3545328B506B"
},
{
"criteria": "cpe:2.3:o:redhat:fedora_core:core_3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC80CF67-C51D-442C-9526-CFEDE84A6304"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}