Comment 18 for bug 1083416

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package cups-pk-helper - 0.2.1.2-1ubuntu0.1

---------------
cups-pk-helper (0.2.1.2-1ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: CUPS function calls were wrapped insecurely, which
    could be used to upload sensitive data to a CUPS resource, or overwrite
    specific files with the content of a CUPS resource. The user would have
    to explicitly approve the action. (LP: #1083416)
    - CVE-2012-4510
    - debian/patches/CVE-2012-4510-part1.patch: Copied from git
    - debian/patches/CVE-2012-4510-part2.patch: Copied from git
 -- Jeremy Bicha <email address hidden> Mon, 26 Nov 2012 22:34:18 -0500