CVE-2013-6891

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
26/01/2014
Last modified:
11/04/2025

Description

lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:* 1.7.0 (including)
cpe:2.3:a:apple:cups:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:apple:cups:1.7.1:b1:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*