1.9
CVSSv2

CVE-2014-5030

Published: 29/07/2014 Updated: 07/01/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

CUPS prior to 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

apple cups 1.7.1

apple cups

apple cups 1.7.3

apple cups 1.7.2

apple cups 1.7.0

apple cups 1.7

Vendor Advisories

CUPS could be made to expose sensitive information, leading to privilege escalation ...
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation For the stable distribution (wheezy), these probl ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface (CVE-2014-2856) It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' ...