CVE-2014-3537

Publication date 17 July 2014

Last updated 24 July 2024


Ubuntu priority

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

Read the notes from the security team

Status

Package Ubuntu Release Status
cups 14.04 LTS trusty
Fixed 1.7.2-0ubuntu1.1
12.04 LTS precise
Fixed 1.5.3-0ubuntu8.4
10.04 LTS lucid
Fixed 1.4.3-1ubuntu1.12

Notes


jdstrand

per upstream, requires web interface to be enabled


mdeslaur

patch in 1.7.4 is slightly different than the one in the bug

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
cups

References

Related Ubuntu Security Notices (USN)

Other references