PT-2009-5180 · Apple+1 · Cups+1
Aaron Sigel
·
Published
2009-11-10
·
Updated
2024-06-15
·
CVE-2009-2820
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CUPS versions prior to 1.4.2
Description
The issue concerns the web interface of CUPS, which does not properly handle HTTP headers and HTML templates. This allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks. The attacks can be conducted via various vectors, including the product's web interface, the configuration of the print system, and the titles of printed jobs. An example of such an attack is an XSS attack that uses the
kerberos parameter to the admin program, leveraging attribute injection and HTTP Parameter Pollution (HPP) issues.Recommendations
For CUPS versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cups
Red Hat