CVE Reference: CVE-2010-0540

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-0540

Description:
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVE Status:
Candidate

References:

ST
  1024122

SAID
  Secunia Advisory: SA40220
  Secunia Advisory: SA43521

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10382

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2010:234
  http://www.mandriva.com/security/advisories?name=MDVSA-2010:233
  http://www.mandriva.com/security/advisories?name=MDVSA-2010:232

GENTOO
  http://security.gentoo.org/glsa/glsa-201207-10.xml

DEBIAN
  http://www.debian.org/security/2011/dsa-2176

CONFIRM
  http://cups.org/str.php?L3498
  http://cups.org/articles.php?L596
  http://support.apple.com/kb/HT4188

BID
  40871

APPLE
  http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html


Return to the previous page.