Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Mac OS X多个缓冲区溢出安全漏洞
Vulnerability Description
Apple Mac OS X是苹果家族电脑所使用的操作系统,Font Book是Mac OS X中所包括的字体管理工具。 Apple Mac OS X的CUPS的网络接口,在处理表单变量时会读取未初始化的内存,攻击者可利用未明向量从过程内存中获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A