Wind River Support Network

HomeDefectsLIN7-4004
Fixed

LIN7-4004 : Security Advisory - cups - CVE-2015-1159

Created: Jun 14, 2015    Updated: Sep 8, 2018
Resolved Date: Jun 18, 2015
Previous ID: LIN4-32740
Found In Version: 7.0.0.5
Fix Version: 7.0.0.7
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

The following flaw was found in CUPS:

A cross-site scripting bug in the CUPS templating engine allows this bug to be exploited when a user browses the web. This XSS is reachable in the default configuration for Linux instances of CUPS, and allows an attacker to bypass default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1159

Other Downloads


CVEs


Live chat
Online