cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
BID:55911
Info
cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
| Bugtraq ID: | 55911 |
| Class: | Race Condition Error |
| CVE: |
CVE-2012-4510 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 12 2012 12:00AM |
| Updated: | Apr 13 2015 09:55PM |
| Credit: | Vincent Untz |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 freedesktop.org cups-pk-helper 0.2.2 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
freedesktop.org cups-pk-helper 0.2.3 |
Discussion
cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
cups-pk-helper is prone to multiple local security vulnerabilities.
Local attackers may be able to upload sensitive data or overwrite specific files in the context of the affected application. Other attacks may also be possible.
cups-pk-helper versions prior 0.2.2 are vulnerable.
cups-pk-helper is prone to multiple local security vulnerabilities.
Local attackers may be able to upload sensitive data or overwrite specific files in the context of the affected application. Other attacks may also be possible.
cups-pk-helper versions prior 0.2.2 are vulnerable.
Solution / Fix
cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva cups-pk-helper-0.2.1-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
References:
References:
- cups-pk-helper Homepage (freedesktop.org)
- Security flaw in cups-pk-helper (CVE-2012-4510) (Vincent Untz)