CVE-2014-3537
Published Jul 23, 2014
Last updated 2 years ago
Overview
- Description
- The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.2
- Impact score
- 2.9
- Exploitability score
- 1.9
- Vector string
- AV:L/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-59
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83BA187A-5E24-4307-93F0-7F1046A6B777", "versionEndIncluding": "1.7.3" }, { "criteria": "cpe:2.3:a:apple:cups:1.7:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "055893FF-4833-4BDC-9C6B-B4BDD0F59942" }, { "criteria": "cpe:2.3:a:apple:cups:1.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F911CF9B-673B-4783-BE33-1D233F75BC1B" }, { "criteria": "cpe:2.3:a:apple:cups:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAD0A09C-DCE7-4873-AC60-68EC747BD1F5" }, { "criteria": "cpe:2.3:a:apple:cups:1.7.1:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54164748-5511-4B90-BD1B-75C0D89532A3" }, { "criteria": "cpe:2.3:a:apple:cups:1.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C950144A-DAAB-4E2E-84A6-9C356CDC8EAC" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7118F616-25CA-4E34-AA13-4D14BB62419F" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5D324C4-97C7-49D3-A809-9EAD4B690C69" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "B5A6F2F3-4894-4392-8296-3B8DD2679084" }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF47C9F0-D8DA-4B55-89EB-9B2C9383ADB9" } ], "operator": "OR" } ] } ]