Upstream information
Description
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entries: 548317, 551563, 574336 SUSE Security Advisories:- SUSE-SR:2009:019, published Tue, 24 Nov 2009 07:00:00 +0000
- SUSE-SR:2009:020, published Tue, 12 Jan 2010 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.0 |
| |
| openSUSE 11.0 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
| |
| SUSE Linux Enterprise 11 GA DEBUGINFO |
| sle11-sdk.x86-64 sles11.ia64 sled11.x86-64 sled11.x86 sles11.x86 sle11-sdk.x86 sles11.ppc sle11-sdk.ppc sle11-sdk.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sles11.s390x sle11-debuginfo.ia64 sle11-debuginfo.ppc sles11.x86-64 sle11-debuginfo.x86-64 sle11-debuginfo.s390x SAT Patch Nr: 1504 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.x86-64 sles11.ia64 sled11.x86-64 sled11.x86 sles11.x86 sle11-sdk.x86 sles11.ppc sle11-sdk.ppc sle11-sdk.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sles11.s390x sle11-debuginfo.ia64 sle11-debuginfo.ppc sles11.x86-64 sle11-debuginfo.x86-64 sle11-debuginfo.s390x SAT Patch Nr: 1504 |
| SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.x86-64 sles11.ia64 sled11.x86-64 sled11.x86 sles11.x86 sle11-sdk.x86 sles11.ppc sle11-sdk.ppc sle11-sdk.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sles11.s390x sle11-debuginfo.ia64 sle11-debuginfo.ppc sles11.x86-64 sle11-debuginfo.x86-64 sle11-debuginfo.s390x SAT Patch Nr: 1504 |
| SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.x86-64 sles11.ia64 sled11.x86-64 sled11.x86 sles11.x86 sle11-sdk.x86 sles11.ppc sle11-sdk.ppc sle11-sdk.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sles11.s390x sle11-debuginfo.ia64 sle11-debuginfo.ppc sles11.x86-64 sle11-debuginfo.x86-64 sle11-debuginfo.s390x SAT Patch Nr: 1504 |
| SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.x86-64 sles11.ia64 sled11.x86-64 sled11.x86 sles11.x86 sle11-sdk.x86 sles11.ppc sle11-sdk.ppc sle11-sdk.s390x sle11-debuginfo.x86 sle11-sdk.ia64 sles11.s390x sle11-debuginfo.ia64 sle11-debuginfo.ppc sles11.x86-64 sle11-debuginfo.x86-64 sle11-debuginfo.s390x SAT Patch Nr: 1504 |
List of products where fixes are in QA
SUSE Linux Enterprise 11 GA DEBUGINFOSUSE Linux Enterprise Desktop 11 GA
SUSE Linux Enterprise SDK 11 GA
SUSE Linux Enterprise Server 11 GA
