Description
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
CVSS vector
AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9Complexity: Low
Confidentiality: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-x338-9gp2-578v: The web interface for CUPS before 1↗2022-05-02 ▶ OSVCVE-2009-0164: The web interface for CUPS before 1↗2009-04-24 ▶ CVEListCVE-2009-0164: The web interface for CUPS before 1↗2009-04-24 ▶ 📋Vendor Advisories
2Red Hatcups: insufficient checking of the HTTP Host: header↗2009-04-16 ▶ DebianCVE-2009-0164: cups - The web interface for CUPS before 1.3.10 does not validate the HTTP Host header ...↗2009 ▶ 💬Community
1BugzillaCVE-2009-0164 cups: insufficient checking of the HTTP Host: header↗2009-03-17 ▶