5.8
CVSSv2

CVE-2012-4510

Published: 20/11/2012 Updated: 05/12/2013
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

cups-pk-helper prior to 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote malicious users to read or overwrite sensitive files using CUPS resources.

Vulnerable Product Search on Vulmon Subscribe to Product

cups-pk-helper project cups-pk-helper

cups-pk-helper project cups-pk-helper 0.2.1

cups-pk-helper project cups-pk-helper 0.0.3

cups-pk-helper project cups-pk-helper 0.0.2

cups-pk-helper project cups-pk-helper 0.1.2

cups-pk-helper project cups-pk-helper 0.1.1

cups-pk-helper project cups-pk-helper 0.2.0

cups-pk-helper project cups-pk-helper 0.1.3

cups-pk-helper project cups-pk-helper 0.0.1

cups-pk-helper project cups-pk-helper 0.1.0

cups-pk-helper project cups-pk-helper 0.0.4

Vendor Advisories

cups-pk-helper, a PolicyKit helper to configure CUPS with fine-grained privileges, wraps CUPS function calls in an insecure way This could lead to uploading sensitive data to a CUPS resource, or overwriting specific files with the content of a CUPS resource The user would have to explicitly approve the action For the stable distribution (squeeze ...