1.2
CVSSv2

CVE-2014-3537

Published: 23/07/2014 Updated: 13/02/2023
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web interface in CUPS prior to 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.7.0

apple cups 1.7.1

apple cups 1.7

apple cups 1.7.2

apple cups

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

fedoraproject fedora 20

canonical ubuntu linux 10.04

Vendor Advisories

CUPS could be made to expose sensitive information, leading to privilege escalation ...
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation For the stable distribution (wheezy), these probl ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface (CVE-2014-2856) It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' ...
It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' group privileges could use this flaw to read the contents of arbitrary files on the system or, potentially, escalate their privileges on the system ...