cve/2014/CVE-2014-5029.md
2024-05-26 14:27:05 +02:00

706 B

CVE-2014-5029

Description

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.

POC

Reference

Github

No PoCs found on GitHub currently.