UbuntuUpdates.org

Package "cups-pk-helper"

Name: cups-pk-helper

Description:

PolicyKit helper to configure cups with fine-grained privileges

Latest version: 0.2.1.2-1ubuntu0.1
Release: precise (12.04)
Level: updates
Repository: universe
Homepage: http://www.freedesktop.org/software/cups-pk-helper/

Links


Download "cups-pk-helper"


Other versions of "cups-pk-helper" in Precise

Repository Area Version
base universe 0.2.1.2-1

Changelog

Version: 0.2.1.2-1ubuntu0.1 2012-12-10 17:07:25 UTC

  cups-pk-helper (0.2.1.2-1ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: CUPS function calls were wrapped insecurely, which
    could be used to upload sensitive data to a CUPS resource, or overwrite
    specific files with the content of a CUPS resource. The user would have
    to explicitly approve the action. (LP: #1083416)
    - CVE-2012-4510
    - debian/patches/CVE-2012-4510-part1.patch: Copied from git
    - debian/patches/CVE-2012-4510-part2.patch: Copied from git
 -- Jeremy Bicha <email address hidden> Mon, 26 Nov 2012 22:34:18 -0500

1083416 cups-pk-helper security vulnerability CVE-2012-4510
CVE-2012-4510 cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attacker



About   -   Send Feedback to @ubuntu_updates