Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.67225
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2010:072 (cups)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to cups
announced via advisory MDVSA-2010:072.

Multiple vulnerabilities has been found and corrected in cups:

CUPS in does not properly handle (1) HTTP headers and (2) HTML
templates, which allows remote attackers to conduct cross-site
scripting (XSS) attacks and HTTP response splitting attacks via vectors
related to (a) the product's web interface, (b) the configuration of
the print system, and (c) the titles of printed jobs (CVE-2009-2820).

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS
1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable
to determine the file that provides localized message strings, which
allows local users to gain privileges via a file that contains crafted
localization data with format string specifiers (CVE-2010-0393).

The updated packages have been patched to correct these issues.

Affected: Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2010:072

Risk factor : High

CVSS Score:
6.9

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-2820
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
BugTraq ID: 36956
http://www.securityfocus.com/bid/36956
http://www.mandriva.com/security/advisories?name=MDVSA-2010:072
http://www.mandriva.com/security/advisories?name=MDVSA-2010:073
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9153
http://www.redhat.com/support/errata/RHSA-2009-1595.html
http://secunia.com/advisories/37308
http://secunia.com/advisories/37360
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021115.1-1
http://www.vupen.com/english/advisories/2009/3184
Common Vulnerability Exposure (CVE) ID: CVE-2010-0393
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
BugTraq ID: 38524
http://www.securityfocus.com/bid/38524
http://security.gentoo.org/glsa/glsa-201207-10.xml
http://www.cups.org/str.php?L3482
http://www.ubuntu.com/usn/USN-906-1
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.