LWN.net Logo

system-config-printer: man-in-the-middle package installation

Package(s):system-config-printer CVE #(s):CVE-2011-4405
Created:November 17, 2011 Updated:November 23, 2011
Description:

From the Ubuntu advisory:

Marc Deslauriers discovered that system-config-printer's cupshelpers scripts used by the Ubuntu automatic printer driver download service queried the OpenPrinting database using an insecure connection. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to install altered packages and repositories.

Alerts:
openSUSE openSUSE-SU-2011:1331-1 2011-12-16
Ubuntu USN-1265-1 2011-11-17
openSUSE openSUSE-SU-2011:1331-2 2012-01-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds