cbcvebase.
CVE-2013-6476
published 2014-03-14

CVE-2013-6476: The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain…

PriorityP417medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.31%
23.5th percentile
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
applecups>= 0 < 1.5.0-161.5.0-16
applecups>= 0 < 1.5.0-161.5.0-16
applecups>= 0 < 1.5.0-161.5.0-16
applecups>= 0 < 1.5.0-161.5.0-16
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancups< cups 1.5.0-16 (bookworm)cups 1.5.0-16 (bookworm)
debiancups-filters< cups 1.5.0-16 (bookworm)cups 1.5.0-16 (bookworm)
linuxfoundationcups-filters<= 1.0.46
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters
linuxfoundationcups-filters

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.