Unrated severityNVD Advisory· Published Jan 26, 2014· Updated Apr 29, 2026
CVE-2013-6891
CVE-2013-6891
Description
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Affected products
6cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*range: <=1.7.0
- cpe:2.3:a:apple:cups:1.7:rc1:*:*:*:*:*:*
- cpe:2.3:a:apple:cups:1.7.1:b1:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.cups.org/str.phpnvdExploitPatch
- secunia.com/advisories/56531nvdVendor Advisory
- advisories.mageia.org/MGASA-2014-0021.htmlnvd
- www.cups.org/blog.phpnvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/USN-2082-1nvd
News mentions
0No linked articles in our index yet.