Jump to content

Advisories MDVSA-2010:072: cups


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in cups:

 

CUPS in does not properly handle (1) HTTP headers and (2) HTML

templates, which allows remote attackers to conduct cross-site

scripting (XSS) attacks and HTTP response splitting attacks via vectors

related to (a) the product's web interface, (B) the configuration of

the print system, and © the titles of printed jobs (CVE-2009-2820).

 

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS

1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable

to determine the file that provides localized message strings, which

allows local users to gain privileges via a file that contains crafted

localization data with format string specifiers (CVE-2010-0393).

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...