CVE-2013-6891: Apple Cups
Low severity, CVSS 1.2. EPSS: 0.4% chance of exploitation in the next 30 days.
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Affected products
- Apple Cups: up to and including 1.7.0; version 1.7 only; version 1.7.1 only
- Canonical Ubuntu Linux: version 12.10 only; version 13.04 only; version 13.10 only
Published 2014-01-26. Last modified 2026-06-17.