CVE-2012-4510 Information

Description

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.

Reference

http://www.debian.org/security/2012/dsa-2562 http://www.mandriva.com/security/advisories?name=MDVSA-2013:069 http://www.openwall.com/lists/oss-security/2012/10/12/2

Share on: