Description
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
CVSS vector
AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9Integrity: None
Availability: None
Affected Packages2 packages
Also affects: Ubuntu Linux 10.04, 12.04, 14.04
🔴Vulnerability Details
4GHSAGHSA-f4q9-g8vj-q74x: CUPS before 2↗2022-05-17 ▶ OSVlibdbi-perl vulnerabilities↗2022-02-03 ▶ OSVCVE-2014-5030: CUPS before 2↗2014-07-29 ▶ CVEListCVE-2014-5030: CUPS before 2↗2014-07-29 ▶ 📋Vendor Advisories
3UbuntuCUPS vulnerabilities↗2014-09-08 ▶ Red Hatcups: allows local users to read arbitrary files via a symlink attack↗2014-07-22 ▶ DebianCVE-2014-5030: cups - CUPS before 2.0 allows local users to read arbitrary files via a symlink attack ...↗2014 ▶ 💬Community
3BugzillaCVE-2014-5030 cups: allows local users to read arbitrary files via a symlink attack↗2014-08-11 ▶ BugzillaCVE-2014-5030 cups: various flaws [fedora-all]↗2014-08-11 ▶ BugzillaCVE-2014-5029 CVE-2014-5030 CVE-2014-5031 cups: Incomplete fix for CVE-2014-3537 [fedora-all]↗2014-07-23 ▶