← Back to browse · API

CVE-2004-2154

Severity
CRITICAL
CVSS
9.8
EPSS
0.02072
Risk score
39.93
CISA KEV
No
PoC
No
Published
2005-07-05
Modified
2024-08-08
First seen
2026-08-07
Aliases
EUVD-2004-2146, GHSA-VP74-83H5-6967
Products
n/a:n/a n/a
Sources
euvd EUVD-2004-2146

Description

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

References