1.5
CVSSv2

CVE-2014-5029

Published: 29/07/2014 Updated: 07/01/2017
CVSS v2 Base Score: 1.5 | Impact Score: 2.9 | Exploitability Score: 2.7
VMScore: 134
Vector: AV:L/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.7.4

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

CUPS could be made to expose sensitive information, leading to privilege escalation ...
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation For the stable distribution (wheezy), these probl ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface (CVE-2014-2856) It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' ...