LWN.net Logo

cups: insecure tmp file usage

Package(s):cups CVE #(s):CVE-2009-0032
Created:January 26, 2009 Updated:January 28, 2009
Description:

From the Mandriva advisory:

A vulnerability has been discovered in CUPS shipped with Mandriva Linux which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file (CVE-2009-0032)

Alerts:
Mandriva MDVSA-2009:029 2009-01-24
Mandriva MDVSA-2009:028 2009-01-24
Mandriva MDVSA-2009:027 2009-01-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds