CVE-2013-6891
Publication date 31 December 2013
Last updated 24 July 2024
Ubuntu priority
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Status
Package | Ubuntu Release | Status |
---|---|---|
cups | 13.10 saucy |
Fixed 1.7.0~rc1-0ubuntu5.2
|
13.04 raring |
Fixed 1.6.2-1ubuntu8
|
|
12.10 quantal |
Fixed 1.6.1-0ubuntu11.5
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
References
Related Ubuntu Security Notices (USN)
- USN-2082-1
- CUPS vulnerability
- 15 January 2014