Back

LOW

cups: lppasswd vulnerability allows data access to unprivileged user

Published Jan 26, 2014

Description

lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 5 and 6 as they did not ship with an suid-root lppasswd binary.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2014
Updated Aug 6, 2024
Reserved Nov 28, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2013