Link following in CUPS - CVE-2013-6891
Published: January 26, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Affected software
cups (Alpine package)
How to mitigate CVE-2013-6891
cups (Alpine package) - update to 1.7.1-r0