CVE-2014-3537
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.4%
EPSS: 2026-05-06
Affects
apple:cupscanonical:ubuntu_linuxfedoraproject:fedoraTechnical description
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
Published: 7/23/2014, 2:55:05 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://advisories.mageia.org/MGASA-2014-0313.html
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-July/135528.html
- http://rhn.redhat.com/errata/RHSA-2014-1388.html
- http://secunia.com/advisories/59945
- http://secunia.com/advisories/60273
- http://secunia.com/advisories/60787
- http://www.cups.org/blog.php?L724