Unrated severityNVD Advisory· Published Jan 26, 2014· Updated Jun 17, 2026
CVE-2013-6891
CVE-2013-6891
Description
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*range: <=1.7.0
- cpe:2.3:a:apple:cups:1.7.1:b1:*:*:*:*:*:*
- cpe:2.3:a:apple:cups:1.7:rc1:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
- Range: <1.7.1
Patches
Vulnerability mechanics
References
6- www.cups.org/str.phpnvdExploitPatch
- secunia.com/advisories/56531nvdVendor Advisory
- advisories.mageia.org/MGASA-2014-0021.htmlnvd
- www.cups.org/blog.phpnvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/USN-2082-1nvd
News mentions
0No linked articles in our index yet.