PT-2008-6327 · Apple · Cups

Kees Cook

·

Published

2008-11-21

·

Updated

2023-12-28

·

CVE-2008-5184

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.3.8
Description The issue allows remote attackers to bypass intended policy and conduct CSRF attacks via the add and cancel RSS subscription functions in the web interface. This occurs because the web interface uses the guest username when a user is not logged on to the web server.
Recommendations For versions prior to 1.3.8, update to version 1.3.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the cgi-bin/admin.c web interface to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2008-5184

Affected Products

Cups