RULE(RULE ID:321990)

Rule General Information
Release Date: 2019-06-25
Rule Name: Apple CUPS Web Interface URL XSS Vulnerability (CVE-2014-2856)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:66788
http://advisories.mageia.org/MGASA-2014-0193.html
http://rhn.redhat.com/errata/RHSA-2014-1388.html
http://www.cups.org/documentation.php/relnotes.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.cups.org/str.php?L4356