CVE-2004-1269 describes a denial-of-service vulnerability in lppasswd within CUPS 1.1.22, affecting Easy Software Products and Red Hat Fedora Core. The flaw occurs when lppasswd fails to remove a temporary passwd.new file after encountering a file-size resource limit, preventing subsequent password changes. This vulnerability has a CVSS score of 5.0, indicating a network-exploitable, low-complexity attack leading to partial availability impact. While not observed in active exploitation (KEV), public exploit code exists via ExploitDB, and it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.4CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.0.4:*:*:*:*:*:*:* | ||
1.0.4_8CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.0.4_8:*:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.1.1:*:*:*:*:*:*:* | ||
1.1.4CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.1.4:*:*:*:*:*:*:* | ||
1.1.4_2CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.1.4_2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.