Information Disclosure Vulnerability in CUPS on Apple Systems
CVE-2010-1748
Currently unrated
What is CVE-2010-1748?
The cgi_initialize_string function in CUPS, used on various Apple platforms, has a vulnerability that improperly handles parameter values containing a '%' character lacking the required hex encoding. This flaw allows attackers to exploit crafted requests to gain unauthorized access to sensitive information stored in the cupsd process memory. Notable examples of this exploit include crafted URL requests that may reveal internal data, posing significant risks to system security.