CVE-2010-1748
published 2010-06-17CVE-2010-1748: The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCPINAN
EXPLOIT
EPSS
6.47%
93.0th percentile
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.3 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vcrj-62jj-6wf5: The cgi_initialize_string function in cgi-bin/var
ghsa_unreviewed·2022-05-17
CVE-2010-1748 [MEDIUM] CWE-119 GHSA-vcrj-62jj-6wf5: The cgi_initialize_string function in cgi-bin/var
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
OSV
CVE-2010-1748: The cgi_initialize_string function in cgi-bin/var
osv·2010-06-17·CVSS 4.3
CVE-2010-1748 [MEDIUM] CVE-2010-1748: The cgi_initialize_string function in cgi-bin/var
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2010-06-21·CVSS 6.0
CVE-2010-0540 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Adrian Pastor and Tim Starling discovered that the CUPS web interface
incorrectly protected against cross-site request forgery (CSRF) attacks. If
an authenticated user were tricked into visiting a malicious website while
logged into CUPS, a remote attacker could modify the CUPS configuration and
possibly steal confidential data. (CVE-2010-0540)
It was discovered that CUPS did not properly handle memory allocations in
the texttops filter. If a user or automated system were tricked into
printing a crafted text file, a remote attacker could cause a denial of
service or possibly execute arbitrary code with privileges of the CUPS user
(lp). (CVE-2010-0542)
Luca Carettoni discovered that the CUPS web interface incorrectly handled
form variables. A remote attacker w
Red Hat
cups: web interface memory disclosure
vendor_redhat·2010-06-14·CVSS 4.3
CVE-2010-1748 [MEDIUM] cups: web interface memory disclosure
cups: web interface memory disclosure
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-1748: cups - The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS...
vendor_debian·2010·CVSS 4.3
CVE-2010-1748 [MEDIUM] CVE-2010-1748: cups - The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS...
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
No detection rules found.
Exploit-DB
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
exploitdb·2010-09-28
CVE-2007-1748 Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
---
##
# $Id: ms07_029_msdns_zonename.rb 10503 2010-09-28 15:23:14Z hdm $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)',
'Description' => %q{
This module exploits a stack buffer overflow in the RPC interface
of the Microsoft DNS service. The vulnerability is triggered
when a long zone name parameter is supplied that contains
escaped octal strings. This module is capable of bypassing
Exploit-DB
Microsoft DNS RPC Service - 'extractQuotedChar()' TCP Overflow (MS07-029) (Metasploit)
exploitdb·2010-07-25
CVE-2007-1748 Microsoft DNS RPC Service - 'extractQuotedChar()' TCP Overflow (MS07-029) (Metasploit)
Microsoft DNS RPC Service - 'extractQuotedChar()' TCP Overflow (MS07-029) (Metasploit)
---
##
# $Id: ms07_029_msdns_zonename.rb 9929 2010-07-25 21:37:54Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)',
'Description' => %q{
This module exploits a stack buffer overflow in the RPC interface
of the Microsoft DNS service. The vulnerability is triggered
when a long zone name parameter is supplied that contains
escaped octal strings. This module is capable of bypassing NX/DEP
p
Exploit-DB
CUPS 1.4.2 - Web Interface Information Disclosure
exploitdb·2010-06-15
CVE-2010-1748 CUPS 1.4.2 - Web Interface Information Disclosure
CUPS 1.4.2 - Web Interface Information Disclosure
---
source: https://www.securityfocus.com/bid/40897/info
CUPS is prone to a remote information-disclosure vulnerability. This issue affects the CUPS web interface component.
Remote attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
NOTE: This issue was previously covered in BID 40871 (Apple Mac OS X Prior to 10.6.4 Multiple Security Vulnerabilities), but has been given its own record to better document it.
http://www.example.com:631/admin?URL=/admin/&OP=%
Bugzilla
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
bugzilla·2010-06-17·CVSS 6.0
CVE-2010-0540 [MEDIUM] CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
CVE-2010-0540 CVE-2010-0542 CVE-2010-1748 CVE-2010-2431 cups various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=591983
Please note: this issue af
Bugzilla
CVE-2010-1748 cups: web interface memory disclosure
bugzilla·2010-05-13·CVSS 4.3
CVE-2010-1748 [MEDIUM] CVE-2010-1748 cups: web interface memory disclosure
CVE-2010-1748 cups: web interface memory disclosure
An unitialized memory read issue exists in the CUPS web interface in how it handles form variables. An attacker with access to the CUPS web interface could possibly read a limited amount of memory from the cupsd process. In cgi-bin/var.c, when processing form variables that can come from an unauthenticated user, the cgi_initialize_string() function expects a 2-character hex code after the % character. If the last character of data is the % character, then it will append a mangled version of the nul terminator and one more byte following the end of data to the output. The loop will continue appending the contents of memory past the end of data to the output, until another nul byte is read. A GET request will disclose memory from the envir
http://cups.org/articles.php?L596http://cups.org/str.php?L3577http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://secunia.com/advisories/40220http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40871http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2011/0535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9723http://cups.org/articles.php?L596http://cups.org/str.php?L3577http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://secunia.com/advisories/40220http://secunia.com/advisories/43521http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://support.apple.com/kb/HT4188http://www.debian.org/security/2011/dsa-2176http://www.mandriva.com/security/advisories?name=MDVSA-2010:232http://www.mandriva.com/security/advisories?name=MDVSA-2010:234http://www.securityfocus.com/bid/40871http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2011/0535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9723
2010-06-17
Published