SB2014012601 - Link following in Apple CUPS
Published: January 26, 2014 Updated: July 28, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2013-6891)
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Remediation
Install update from vendor's website.