Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1748

Опубликовано: 17 июн. 2010
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3

Описание

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.4.4-1
hardy

DNE

jaunty

released

1.3.9-17ubuntu3.9
karmic

released

1.4.1-5ubuntu2.6
lucid

released

1.4.3-1ubuntu1.2
upstream

released

1.4.4

Показывать по

РелизСтатусПримечание
dapper

released

1.2.2-0ubuntu0.6.06.19
devel

DNE

hardy

released

1.3.7-1ubuntu3.11
jaunty

DNE

karmic

DNE

lucid

DNE

upstream

released

1.4.4

Показывать по

EPSS

Процентиль: 94%
0.13402
Средний

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

nvd
около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

debian
около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interfa ...

github
около 3 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

oracle-oval
около 15 лет назад

ELSA-2010-0490: cups security update (IMPORTANT)

EPSS

Процентиль: 94%
0.13402
Средний

4.3 Medium

CVSS2

Уязвимость CVE-2010-1748