Description
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =2.4.10-1 || =2.4.10-2 || =2.4.10-3 || =2.4.10-4 || =2.4.14-1 || =2.4.15-1 || =2.4.16-1 || =2.4.17-1 || =2.4.18-1 || =2.4.2-3 || =2.4.2-3+deb12u1 || =2.4.2-3+deb12u2 || =2.4.2-3+deb12u3 || =2.4.2-3+deb12u4 || =2.4.2-3+deb12u5 || =2.4.2-3+deb12u6 || =2.4.2-3+deb12u7 || =2.4.2-3+deb12u8 || =2.4.2-3+deb12u9 || =2.4.2-4 || =2.4.2-5 || =2.4.2-6 || =2.4.7-1 || =2.4.7-1.1 || =2.4.7-1.2 || =2.4.7-2 || =2.4.7-3 |
 debian 13 | | =2.4.10-3 || =2.4.10-3+deb13u1 || =2.4.10-3+deb13u2 || =2.4.10-4 || =2.4.14-1 || =2.4.15-1 || =2.4.16-1 || =2.4.17-1 || =2.4.18-1 |
 debian 14 | | =2.4.10-3 || =2.4.10-4 || =2.4.14-1 || =2.4.15-1 || =2.4.16-1 || =2.4.17-1 || =2.4.18-1 |
 rpm rhel8 | | - |
 rpm rhel9 | | - |
 rpm rhel10 | | - |
 rpm rhel6 | | - |
 rpm rhel7 | | - |