CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
| Software | From | Fixed in |
|---|---|---|
| apple / cups | - | 1.1.21 |
| apple / cups | 1.1.21 | 1.1.21.x |
| canonical / ubuntu_linux | 4.10 | 4.10.x |