CVE-2010-0540
published 2010-06-17CVE-2010-0540: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and…
PriorityP425medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.27%
66.9th percentile
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.4.4-1 | 1.4.4-1 |
| apple | cups | >= 0 < 1.4.4-1 | 1.4.4-1 |
| apple | cups | >= 0 < 1.4.4-1 | 1.4.4-1 |
| apple | cups | >= 0 < 1.4.4-1 | 1.4.4-1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| debian | cups | < cups 1.4.4-1 (bookworm) | cups 1.4.4-1 (bookworm) |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfwh-42mw-69v8: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1
ghsa_unreviewed·2022-05-02
CVE-2010-0540 [MEDIUM] CWE-352 GHSA-hfwh-42mw-69v8: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
OSV
CVE-2010-0540: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1
osv·2010-06-17·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-06-21·CVSS 6.0
CVE-2010-0540 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Adrian Pastor and Tim Starling discovered that the CUPS web interface
incorrectly protected against cross-site request forgery (CSRF) attacks. If
an authenticated user were tricked into visiting a malicious website while
logged into CUPS, a remote attacker could modify the CUPS configuration and
possibly steal confidential data. (CVE-2010-0540)
It was discovered that CUPS did not properly handle memory allocations in
the texttops filter. If a user or automated system were tricked into
printing a crafted text file, a remote attacker could cause a denial of
service or possibly execute arbitrary code with privileges of the CUPS user
(lp). (CVE-2010-0542)
Luca Carettoni discovered that the CUPS web interface incorrectly handled
form variables. A remote attacker w
Red Hat
CUPS administrator web interface CSRF
vendor_redhat·2010-06-15·CVSS 6.0
CVE-2010-0540 [MEDIUM] CWE-352 CUPS administrator web interface CSRF
CUPS administrator web interface CSRF
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0540: cups - Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS bef...
vendor_debian·2010·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540: cups - Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS bef...
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
bugzilla·2010-06-17·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=591983
Please note: this issue af
Bugzilla
CVE-2010-0540 CUPS administrator web interface CSRF
bugzilla·2010-05-04·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540 CUPS administrator web interface CSRF
CVE-2010-0540 CUPS administrator web interface CSRF
Impact: Visiting a maliciously crafted website while logged into the CUPS
web interface as an administrator may lead to CUPS being reconfigured
Description: A cross-site request forgery issue exists in the CUPS web
interface. Visiting a maliciously crafted website while logged into the
CUPS web interface as an administrator may lead to CUPS being reconfigured.
This issue is addressed by requiring web form submissions to include an
unpredictable session token. Credit to Adrian 'pagvac' Pastor of
GNUCITIZEN, and Tim Starling for reporting this issue.
The CUPS web interface allows you to edit cupsd.conf and manipulate print
queues and jobs. If an authenticated administrator visits an attacker's
website, the attacker can disable the cupsd
http://cups.org/articles.php?L596http://cups.org/str.php?L3498http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://secunia.com/advisories/40220http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:233http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40871http://www.securitytracker.com/id?1024122http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2011/0535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10382http://cups.org/articles.php?L596http://cups.org/str.php?L3498http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://secunia.com/advisories/40220http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:233http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40871http://www.securitytracker.com/id?1024122http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2011/0535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10382
2010-06-17
Published