LWN.net Logo

cups: insecure tmp file usage

Package(s):cups, cupsys CVE #(s):CVE-2008-5377
Created:January 12, 2009 Updated:January 14, 2009
Description:

From the Ubuntu advisory:

It was discovered that the example pstopdf CUPS filter created log files in an insecure way. Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program.

Alerts:
Ubuntu USN-707-1 2009-01-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds