4.3
CVSSv2

CVE-2010-1748

Published: 17/06/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS prior to 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 prior to 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent malicious users to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.1.6

apple cups 1.1.6-1

apple cups 1.1.10

apple cups 1.1.6-3

apple cups 1.1.17

apple cups 1.1.12

apple cups 1.1.19

apple cups 1.1.20

apple cups 1.1.21

apple cups 1.2

apple cups 1.2.5

apple cups 1.2.4

apple cups 1.2.9

apple cups 1.2.10

apple cups 1.3.0

apple cups 1.4.0

apple cups 1.3.7

apple cups 1.3.10

apple cups 1.3.6

apple cups 1.1.2

apple cups 1.1.3

apple cups 1.1.4

apple cups 1.1.6-2

apple cups 1.1.8

apple cups 1.1.11

apple cups 1.1.14

apple cups 1.4.1

apple cups 1.2.3

apple cups 1.2.2

apple cups 1.2.11

apple cups 1.2.12

apple cups 1.3.1

apple cups 1.3.11

apple cups

apple cups 1.1.5-1

apple cups 1.1.5-2

apple cups 1.1.9-1

apple cups 1.1.10-1

apple cups 1.1.15

apple cups 1.1.18

apple cups 1.1.22

apple cups 1.2.0

apple cups 1.2.7

apple cups 1.2.8

apple cups 1.4.2

apple cups 1.3

apple cups 1.3.4

apple cups 1.3.5

apple cups 1.3.8

apple cups 1.1

apple cups 1.1.1

apple cups 1.1.5

apple cups 1.1.9

apple cups 1.1.7

apple cups 1.1.16

apple cups 1.1.13

apple cups 1.1.23

apple cups 1.2.1

apple cups 1.2.6

apple cups 1.3.9

apple cups 1.3.2

apple cups 1.3.3

Vendor Advisories

Adrian Pastor and Tim Starling discovered that the CUPS web interface incorrectly protected against cross-site request forgery (CSRF) attacks If an authenticated user were tricked into visiting a malicious website while logged into CUPS, a remote attacker could modify the CUPS configuration and possibly steal confidential data (CVE-2010-0540) ...
Several vulnerabilities have been discovered in the Common UNIX Printing System: CVE-2008-5183 A null pointer dereference in RSS job completion notifications could lead to denial of service CVE-2009-3553 It was discovered that incorrect file descriptor handling could lead to denial of service CVE-2010-0540 A cross-site request for ...

Exploits

source: wwwsecurityfocuscom/bid/40897/info CUPS is prone to a remote information-disclosure vulnerability This issue affects the CUPS web interface component Remote attackers can exploit this issue to obtain sensitive information that may lead to further attacks NOTE: This issue was previously covered in BID 40871 (Apple Mac OS X Pri ...