SB2014020522 - Link following in cups (Alpine package)
Published: February 5, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2013-6891)
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Remediation
Install update from vendor's website.