CVE-2013-6891
Publication date 31 December 2013
Last updated 24 July 2024
Ubuntu priority
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
References
Related Ubuntu Security Notices (USN)
- USN-2082-1
- CUPS vulnerability
- 15 January 2014