Wind River Support Network


LIN6-9992 : Security Advisory - cups - CVE-2015-1159

Created: Jun 14, 2015    Updated: Dec 3, 2018
Resolved Date: Jun 18, 2015
Previous ID: LIN4-32739
Found In Version:
Fix Version:
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace


The following flaw was found in CUPS:

A cross-site scripting bug in the CUPS templating engine allows this bug to be exploited when a user browses the web. This XSS is reachable in the default configuration for Linux instances of CUPS, and allows an attacker to bypass default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface.

Other Downloads

Live chat