CVE-2014-2856 (retired)

Priority
Description
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common
Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject
arbitrary web script or HTML via the URL path, related to the
is_path_absolute function.
Notes
 mdeslaur> successfully reproduced on lucid+
 mdeslaur> patch in bug is what's in 1.7.2
Assigned-to
mdeslaur
Package
Source: cups (LP Ubuntu Debian)
Upstream:released (1.7.2)
Ubuntu 14.04 LTS (Trusty Tahr):released (1.7.2-0ubuntu1)
Patches:
Upstream:http://www.cups.org/strfiles.php/3268/str4356.patch
More Information

Updated: 2019-03-26 12:12:58 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)