CVE-2014-2856
Publication date 18 April 2014
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Status
Package | Ubuntu Release | Status |
---|---|---|
cups | 14.04 LTS trusty |
Fixed 1.7.2-0ubuntu1
|
Notes
Patch details
Package | Patch details |
---|---|
cups |
References
Related Ubuntu Security Notices (USN)
- USN-2172-1
- CUPS vulnerability
- 24 April 2014