cbcvebase.
CVE-2013-6891
published 2014-01-26

CVE-2013-6891: lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment…

low1.2CVSS 3.1
AVLACHAuNCPINAN
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.

Affected

11 ranges
VendorProductVersion rangeFixed in
applecups<= 1.7.0
applecups
applecups
applecups>= 0 < 1.7.1-11.7.1-1
applecups>= 0 < 1.7.1-11.7.1-1
applecups>= 0 < 1.7.1-11.7.1-1
applecups>= 0 < 1.7.1-11.7.1-1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancups< cups 1.7.1-1 (bookworm)cups 1.7.1-1 (bookworm)

CVSS provenance

nvd1.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW