CVE detail
CVE-2004-1270 — CVE-2004-1270
Published 2005-01-10 · Modified 2026-06-16 · Vendor easy_software_products · Product cups · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0045
EPSS probability
exploitation probability, 30d
37.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References