LWN.net Logo

cups-pk-helper: privilege escalation

Package(s):cups-pk-helper CVE #(s):CVE-2012-4510
Created:October 24, 2012 Updated:April 9, 2013
Description: From the Debian advisory:

cups-pk-helper, a PolicyKit helper to configure cups with fine-grained privileges, wraps CUPS function calls in an insecure way. This could lead to uploading sensitive data to a cups resource, or overwriting specific files with the content of a cups resource. The user would have to explicitly approve the action.

Alerts:
Debian DSA-2562-1 2012-10-23
Mageia MGASA-2012-0310 2012-10-29
Fedora FEDORA-2012-18950 2012-12-11
Fedora FEDORA-2012-18927 2012-12-11
Mandriva MDVSA-2013:069 2013-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds