Definition


New Search

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4 as used on Apple Mac OS X 10.5.8 Mac OS X 10.6 before 10.6.4 and other platforms does not properly handle parameter values containing a % (percent) character without two subsequent hex characters which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request as demonstated by the (1) /admin?OP=redirectURL=% and (2) /admin?URL=/admin/OP=% URIs.

oval:org.mitre.oval:def:9723

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4 as used on Apple Mac OS X 10.5.8 Mac OS X 10.6 before 10.6.4 and other platforms does not properly handle parameter values containing a % (percent) character without two subsequent hex characters which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Red Hat Enterprise Linux 3
  • CentOS Linux 5
  • Red Hat Enterprise Linux 4
  • Oracle Linux 4
  • Red Hat Enterprise Linux 5
  • CentOS Linux 4
  • CentOS Linux 3
  • Oracle Linux 5
Class:
vulnerability
Reference(s):
  • CVE-2010-1748
Product(s):