Total vulnerabilities in the database
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Software | From | Fixed in |
---|---|---|
apple / cups | 1.7.1-b1 | 1.7.1-b1.x |
apple / cups | 1.7-rc1 | 1.7-rc1.x |
apple / cups | - | 1.7.0.x |
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 13.10 | 13.10.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |