CVE-2014-2856
published 2014-04-18CVE-2014-2856: Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.64%
73.9th percentile
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.7.1 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2014-04-24
CVE-2014-2856 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to expose sensitive information over the network.
Alex Korobkin discovered that the CUPS web interface incorrectly protected
against cross-site scripting (XSS) attacks. If an authenticated user were
tricked into visiting a malicious website while logged into CUPS, a remote
attacker could modify the CUPS configuration and possibly steal
confidential data.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: cross-site scripting flaw fixed in the 1.7.2 release
vendor_redhat·2014-01-30·CVSS 4.3
CVE-2014-2856 [MEDIUM] CWE-79 cups: cross-site scripting flaw fixed in the 1.7.2 release
cups: cross-site scripting flaw fixed in the 1.7.2 release
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
A cross-site scripting (XSS) flaw was found in the CUPS web interface. An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface.
Statement: This issue is not planned to be fixed in Red Hat Enterprise Linux 5 as it is now in Production 3 Phase of the support and maintenance life cycle, https://access.redhat.com/support/policy/updates/errata/
Package: cups (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2014-2856: cups - Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Pr...
vendor_debian·2014·CVSS 4.3
CVE-2014-2856 [MEDIUM] CVE-2014-2856: cups - Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Pr...
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Scope: local
bookworm: resolved (fixed in 1.7.2-1)
bullseye: resolved (fixed in 1.7.2-1)
forky: resolved (fixed in 1.7.2-1)
sid: resolved (fixed in 1.7.2-1)
trixie: resolved (fixed in 1.7.2-1)
GHSA
GHSA-5rr9-vfp7-m4m5: Cross-site scripting (XSS) vulnerability in scheduler/client
ghsa_unreviewed·2022-05-17
CVE-2014-2856 [MEDIUM] CWE-79 GHSA-5rr9-vfp7-m4m5: Cross-site scripting (XSS) vulnerability in scheduler/client
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
OSV
eglibc, glibc vulnerabilities
osv·2016-05-25·CVSS 2.6
CVE-2013-2207 eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE
OSV
CVE-2014-2856: Cross-site scripting (XSS) vulnerability in scheduler/client
osv·2014-04-18·CVSS 4.3
CVE-2014-2856 [MEDIUM] CVE-2014-2856: Cross-site scripting (XSS) vulnerability in scheduler/client
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1388.htmlhttp://secunia.com/advisories/57880http://www.cups.org/documentation.php/relnotes.htmlhttp://www.cups.org/str.php?L4356http://www.mandriva.com/security/advisories?name=MDVSA-2015:108http://www.openwall.com/lists/oss-security/2014/04/14/2http://www.openwall.com/lists/oss-security/2014/04/15/3http://www.securityfocus.com/bid/66788http://www.ubuntu.com/usn/USN-2172-1http://advisories.mageia.org/MGASA-2014-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1388.htmlhttp://secunia.com/advisories/57880http://www.cups.org/documentation.php/relnotes.htmlhttp://www.cups.org/str.php?L4356http://www.mandriva.com/security/advisories?name=MDVSA-2015:108http://www.openwall.com/lists/oss-security/2014/04/14/2http://www.openwall.com/lists/oss-security/2014/04/15/3http://www.securityfocus.com/bid/66788http://www.ubuntu.com/usn/USN-2172-1
2014-04-18
Published