[v2.7] cups: local leak (CVE-2013-6891)
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
•CONFIRM: http://www.cups.org/blog.php?L704
•CONFIRM: http://www.cups.org/str.php?L4319
•UBUNTU:USN-2082-1
•URL: http://www.ubuntu.com/usn/USN-2082-1
•SECUNIA:56531
•URL: http://secunia.com/advisories/56531
(from redmine: issue id 2657, created on 2014-02-04, closed on 2014-02-05)
- Relations:
- parent #2653 (closed)
- Changesets:
- Revision 463d66f4 by Natanael Copa on 2014-02-05T13:06:33Z:
main/cups: security upgrade to 1.7.1 (CVE-2013-6891)
fixes #2657