1.2
CVSSv2

CVE-2013-6891

Published: 26/01/2014 Updated: 06/03/2014
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

lppasswd in CUPS prior to 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups

apple cups 1.7

apple cups 1.7.1

canonical ubuntu linux 12.10

canonical ubuntu linux 13.04

canonical ubuntu linux 13.10

Vendor Advisories

CUPS could be made to expose sensitive information ...
lppasswd in CUPS before 171, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving cups/clientconf ...