PT-2009-5180 · Apple+1 · Cups+1

Aaron Sigel

·

Published

2009-11-10

·

Updated

2024-06-15

·

CVE-2009-2820

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.4.2
Description The issue concerns the web interface of CUPS, which does not properly handle HTTP headers and HTML templates. This allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks. The attacks can be conducted via various vectors, including the product's web interface, the configuration of the print system, and the titles of printed jobs. An example of such an attack is an XSS attack that uses the kerberos parameter to the admin program, leveraging attribute injection and HTTP Parameter Pollution (HPP) issues.
Recommendations For CUPS versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2820
DSA-1933-1
OPENSUSE-SU-2024:10075-1
RHSA-2009:1595
RHSA-2009_1595

Affected Products

Cups
Red Hat