CVE-2014-3537

Published Jul 23, 2014

Last updated 18 days ago

Overview

Description
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
Source
secalert@redhat.com
NVD status
Modified
Products
cups, ubuntu_linux, fedora

Risk scores

CVSS 2.0

Type
Primary
Base score
1.2
Impact score
2.9
Exploitability score
1.9
Vector string
AV:L/AC:H/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-59

Social media

Hype score
Not currently trending

Configurations