CVE Vulnerabilities

CVE-2012-4510

Published: Nov 20, 2012 | Modified: Dec 05, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.6 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:N
RedHat/V3
Ubuntu
MEDIUM

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.

Affected Software

Name Vendor Start Version End Version
Cups-pk-helper Cups-pk-helper_project * 0.2.2 (including)
Cups-pk-helper Cups-pk-helper_project 0.0.1 (including) 0.0.1 (including)
Cups-pk-helper Cups-pk-helper_project 0.0.2 (including) 0.0.2 (including)
Cups-pk-helper Cups-pk-helper_project 0.0.3 (including) 0.0.3 (including)
Cups-pk-helper Cups-pk-helper_project 0.0.4 (including) 0.0.4 (including)
Cups-pk-helper Cups-pk-helper_project 0.1.0 (including) 0.1.0 (including)
Cups-pk-helper Cups-pk-helper_project 0.1.1 (including) 0.1.1 (including)
Cups-pk-helper Cups-pk-helper_project 0.1.2 (including) 0.1.2 (including)
Cups-pk-helper Cups-pk-helper_project 0.1.3 (including) 0.1.3 (including)
Cups-pk-helper Cups-pk-helper_project 0.2.0 (including) 0.2.0 (including)
Cups-pk-helper Cups-pk-helper_project 0.2.1 (including) 0.2.1 (including)
Cups-pk-helper Ubuntu natty *
Cups-pk-helper Ubuntu oneiric *
Cups-pk-helper Ubuntu precise *
Cups-pk-helper Ubuntu quantal *
Cups-pk-helper Ubuntu upstream *

References