Skip to content

CVE-2014-3537

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.4%
EPSS: 2026-05-06

Affects

apple:cupscanonical:ubuntu_linuxfedoraproject:fedora

Technical description

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

Published: 7/23/2014, 2:55:05 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam