[v2.7] cups: local leak (CVE-2013-6891)
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
(from redmine: issue id 2657, created on 2014-02-04, closed on 2014-02-05)
- parent #2653 (closed)
- Revision 463d66f4 by Natanael Copa on 2014-02-05T13:06:33Z:
main/cups: security upgrade to 1.7.1 (CVE-2013-6891) fixes #2657