Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1033

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2008-1033
Last Modified 16 Jun 2011 12:00:00
Published 02 Jun 2008 05:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity HIGH
Authentication SINGLE_INSTANCE

CVE-2008-1033

Summary

The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."

Vulnerable Systems

Application

  • Apple Cups


References

CERT - TA08-150A

XF - macosx-cups-info-disclosure(42713)

VUPEN - ADV-2008-1697

BID - 29484

BID - 29412

SECTRACK - 1020145

SECUNIA - 30430

APPLE - APPLE-SA-2008-05-28

Related Patches

Apple 2008-05-28 Mac OS X Server 10.5.3 Combo Update

Apple 2008-05-28 Mac OS X Server 10.5.3 Update

Apple 2008-05-28 Mac OS X 10.5.3 Combo Update (Rev 2)

Apple 2008-05-28 Mac OS X 10.5.3 Update


Last Updated: 27 May 2016 10:47:01