CVE-2014-2856
Published: 18 April 2014
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Notes
Author | Note |
---|---|
mdeslaur | successfully reproduced on lucid+ patch in bug is what's in 1.7.2 |
Priority
Status
Package | Release | Status |
---|---|---|
cups Launchpad, Ubuntu, Debian |
lucid |
Released
(1.4.3-1ubuntu1.11)
|
precise |
Released
(1.5.3-0ubuntu8.2)
|
|
quantal |
Released
(1.6.1-0ubuntu11.6)
|
|
saucy |
Released
(1.7.0~rc1-0ubuntu5.3)
|
|
trusty |
Released
(1.7.2-0ubuntu1)
|
|
upstream |
Released
(1.7.2)
|
|
Patches: upstream: http://www.cups.org/strfiles.php/3268/str4356.patch |