CVE-2013-6891
published 2014-01-26CVE-2013-6891: lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment…
PriorityP411low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.45%
36.4th percentile
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.7.0 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | >= 0 < 1.7.1-1 | 1.7.1-1 |
| apple | cups | >= 0 < 1.7.1-1 | 1.7.1-1 |
| apple | cups | >= 0 < 1.7.1-1 | 1.7.1-1 |
| apple | cups | >= 0 < 1.7.1-1 | 1.7.1-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < cups 1.7.1-1 (bookworm) | cups 1.7.1-1 (bookworm) |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2014-01-15
CVE-2013-6891 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to expose sensitive information.
Jann Horn discovered that the CUPS lppasswd tool incorrectly read a user
configuration file in certain configurations. A local attacker could use
this to read sensitive information from certain files, bypassing access
restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: lppasswd vulnerability allows data access to unprivileged user
vendor_redhat·2013-12-19·CVSS 1.2
CVE-2013-6891 [LOW] cups: lppasswd vulnerability allows data access to unprivileged user
cups: lppasswd vulnerability allows data access to unprivileged user
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Statement: Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 5 and 6 as they did not ship with an suid-root lppasswd binary.
Package: cups (Red Hat Enterprise Linux 5) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Package: cups (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6891: cups - lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local...
vendor_debian·2013·CVSS 1.2
CVE-2013-6891 [LOW] CVE-2013-6891: cups - lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local...
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Scope: local
bookworm: resolved (fixed in 1.7.1-1)
bullseye: resolved (fixed in 1.7.1-1)
forky: resolved (fixed in 1.7.1-1)
sid: resolved (fixed in 1.7.1-1)
trixie: resolved (fixed in 1.7.1-1)
GHSA
GHSA-r8jg-q736-v263: lppasswd in CUPS before 1
ghsa_unreviewed·2022-05-17
CVE-2013-6891 [LOW] CWE-59 GHSA-r8jg-q736-v263: lppasswd in CUPS before 1
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
OSV
CVE-2013-6891: lppasswd in CUPS before 1
osv·2014-01-26·CVSS 1.2
CVE-2013-6891 [LOW] CVE-2013-6891: lppasswd in CUPS before 1
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0021.htmlhttp://secunia.com/advisories/56531http://www.cups.org/blog.php?L704http://www.cups.org/str.php?L4319http://www.mandriva.com/security/advisories?name=MDVSA-2014:015http://www.ubuntu.com/usn/USN-2082-1http://advisories.mageia.org/MGASA-2014-0021.htmlhttp://secunia.com/advisories/56531http://www.cups.org/blog.php?L704http://www.cups.org/str.php?L4319http://www.mandriva.com/security/advisories?name=MDVSA-2014:015http://www.ubuntu.com/usn/USN-2082-1
2014-01-26
Published