CVE-2010-0540

Loading...

General

Score:6.0/10.0
Severity:Medium
Category:Bounce Attack

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Medium
Authentication:Multiple

Relative vulnerabilities

CVE-2008-5183, CVE-2009-1578, CVE-2009-1579, CVE-2009-1580, CVE-2009-1581, CVE-2009-2964, CVE-2009-3553, CVE-2009-4212, CVE-2010-0186, CVE-2010-0187, CVE-2010-0283, CVE-2010-0302, CVE-2010-0541, CVE-2010-0542, CVE-2010-0543, CVE-2010-0545, CVE-2010-0546, CVE-2010-0734, CVE-2010-1320, CVE-2010-1373, CVE-2010-1374, CVE-2010-1375, CVE-2010-1376, CVE-2010-1377, CVE-2010-1379, CVE-2010-1380, CVE-2010-1381, CVE-2010-1382, CVE-2010-1411, CVE-2010-1748, CVE-2010-2431, CVE-2010-2432, CVE-2010-2941

Published on 17/06/10 - Updated on 19/09/17

Description

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

Category: Bounce Attack

CWE-352 (Cross-Site Request Forgery (CSRF))
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Security Notices

US National Vulnerability DatabaseCVE-2010-0540
Agence Nationale de la Sécurité des Systèmes d'Information CERTA-2010-AVI-265, CERTA-2010-AVI-275
CentOS CESA-2010:0490
Debian DSA-2176-1
Oracle Linux ELSA-2010-0490
Redhat RHSA-2010:0490
Renater 2010/VULN208, 2011/VULN168

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
applemac_os_x
applemac_os_x_server

Share this vulnerability with:

Twitter Facebook LinkedIn Mail