5
CVSSv2

CVE-2014-5031

Published: 29/07/2014 Updated: 07/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web interface in CUPS prior to 2.0 does not check that files have world-readable permissions, which allows remote malicious users to obtains sensitive information via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.7.1

apple cups 1.7.0

apple cups

apple cups 1.7.3

apple cups 1.7.2

apple cups 1.7

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

CUPS could be made to expose sensitive information, leading to privilege escalation ...
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation For the stable distribution (wheezy), these probl ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface (CVE-2014-2856) It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' ...