Definition
New Search
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4 as used on Apple Mac OS X 10.5.8 Mac OS X 10.6 before 10.6.4 and other platforms does not properly handle parameter values containing a % (percent) character without two subsequent hex characters which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request as demonstated by the (1) /admin?OP=redirectURL=% and (2) /admin?URL=/admin/OP=% URIs.
oval:org.mitre.oval:def:9723
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4 as used on Apple Mac OS X 10.5.8 Mac OS X 10.6 before 10.6.4 and other platforms does not properly handle parameter values containing a % (percent) character without two subsequent hex characters which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
Family:
unix
Status:
ACCEPTED
Platform(s):
- Red Hat Enterprise Linux 3
- Oracle Linux 5
- CentOS Linux 3
- Red Hat Enterprise Linux 4
- Oracle Linux 4
- CentOS Linux 5
- CentOS Linux 4
- Red Hat Enterprise Linux 5
Class:
vulnerability
Reference(s):
- CVE-2010-1748
Product(s):