Wind River Support Network

HomeDefectsLIN5-20517
Fixed

LIN5-20517 : Security Advisory - cups - CVE-2015-1159

Created: Jun 14, 2015    Updated: Dec 19, 2017
Resolved Date: Jun 18, 2015
Previous ID: LIN4-32738
Found In Version: 5.0.1.26
Fix Version: 5.0.1.28
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

The following flaw was found in CUPS:

A cross-site scripting bug in the CUPS templating engine allows this bug to be exploited when a user browses the web. This XSS is reachable in the default configuration for Linux instances of CUPS, and allows an attacker to bypass default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1159

Other Downloads


Live chat
Online