CVE-2008-5184
N/A
N/A
Summary
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.openwall.com/lists/oss-security/2008/11/19/3
- http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/
- http://www.cups.org/str.php?L2774
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:028
References
- http://www.openwall.com/lists/oss-security/2008/11/19/3
- http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/
- http://www.cups.org/str.php?L2774
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:028
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.