{ "id": "CVE-2010-0540", "sourceIdentifier": "product-security@apple.com", "published": "2010-06-17T16:30:01.327", "lastModified": "2017-09-19T01:30:26.470", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings." }, { "lang": "es", "value": "Una vulnerabilidad de falsificaci\u00f3n de petici\u00f3n en sitios cruzados (CSRF) en el interfaz web de CUPS en Apple Mac OS X v10.5.8 y a10.6 antes de 10.6.4, permite a atacantes remotos secuestrar la autenticaci\u00f3n de los administradores durante las peticiones de cambio la configuraci\u00f3n." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 6.8, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-352" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*", "matchCriteriaId": "1335E35A-D381-4056-9E78-37BC6DF8AD98" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x:10.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "3C69DEE9-3FA5-408E-AD27-F5E7043F852A" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "D25D1FD3-C291-492C-83A7-0AFAFAADC98D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "5B565F77-C310-4B83-B098-22F9489C226C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x:10.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "546EBFC8-79F0-42C2-9B9A-A76CA3F19470" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*", "matchCriteriaId": "82B4CD59-9F37-4EF0-BA43-427CFD6E1329" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "26E34E35-CCE9-42BE-9AFF-561D8AA90E25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "A04FF6EE-D4DA-4D70-B0CE-154292828531" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "9425320F-D119-49EB-9265-3159070DFE93" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "F6BE138D-619B-4E44-BFB2-8DFE5F0D1E12" } ] } ] } ], "references": [ { "url": "http://cups.org/articles.php?L596", "source": "product-security@apple.com" }, { "url": "http://cups.org/str.php?L3498", "source": "product-security@apple.com" }, { "url": "http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://security.gentoo.org/glsa/glsa-201207-10.xml", "source": "product-security@apple.com" }, { "url": "http://support.apple.com/kb/HT4188", "source": "product-security@apple.com", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.debian.org/security/2011/dsa-2176", "source": "product-security@apple.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:232", "source": "product-security@apple.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:233", "source": "product-security@apple.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:234", "source": "product-security@apple.com" }, { "url": "http://www.securityfocus.com/bid/40871", "source": "product-security@apple.com", "tags": [ "Patch" ] }, { "url": "http://www.securitytracker.com/id?1024122", "source": "product-security@apple.com" }, { "url": "http://www.vupen.com/english/advisories/2010/1481", "source": "product-security@apple.com", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.vupen.com/english/advisories/2011/0535", "source": "product-security@apple.com" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10382", "source": "product-security@apple.com" } ] }