CUPS Web Interface Cross Site Scripting Vulnerability
BID:66788
Info
CUPS Web Interface Cross Site Scripting Vulnerability
| Bugtraq ID: | 66788 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2856 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2014 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | Alex Korobkin |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Oracle Solaris 11.2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Apple CUPS 1.6.4 |
| Not Vulnerable: |
Oracle Solaris 11.2.4.6.0 Apple CUPS 1.7.2 |
Discussion
CUPS Web Interface Cross Site Scripting Vulnerability
CUPS is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
CUPS 1.6.4 is vulnerable; other versions may also be affected.
CUPS is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
CUPS 1.6.4 is vulnerable; other versions may also be affected.
Exploit / POC
CUPS Web Interface Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
CUPS Web Interface Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva cups-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-common-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-serial-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cups2-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cups2-devel-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cups-1.3.10-0.7mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva cups-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-common-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-serial-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libcups2-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libcups2-devel-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cups-1.3.10-0.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva cups-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-common-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cups-serial-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cups2-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cups2-devel-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cups-1.5.4-1.4.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/