CVE-2014-2856

Priority
Medium
Description
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common
Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject
arbitrary web script or HTML via the URL path, related to the
is_path_absolute function.
References
Bugs
Notes
mdeslaur> successfully reproduced on lucid+
mdeslaur> patch in bug is what's in 1.7.2
Assigned-to
mdeslaur
Package
Source: cups (LP Ubuntu Debian)
Upstream:released (1.7.2)
Ubuntu 10.04 LTS (Lucid Lynx):released (1.4.3-1ubuntu1.11)
Ubuntu 12.04 LTS (Precise Pangolin):released (1.5.3-0ubuntu8.2)
Ubuntu 12.10 (Quantal Quetzal):released (1.6.1-0ubuntu11.6)
Ubuntu 13.10 (Saucy Salamander):released (1.7.0~rc1-0ubuntu5.3)
Ubuntu 14.04 LTS (Trusty Tahr):released (1.7.2-0ubuntu1)
Ubuntu 14.10 (Utopic Unicorn):released (1.7.2-0ubuntu1)
Patches:
Upstream:http://www.cups.org/strfiles.php/3268/str4356.patch
More Information

Valid XHTML 1.0 Strict

Updated: 2014-04-24 16:14:38 UTC (commit 7971)