PT-2012-1034 · Cups · Cups-Pk-Helper

Vincent Untz

·

Publicado

2012-11-20

·

Atualizado

2024-06-15

·

CVE-2012-4510

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions cups-pk-helper versions prior to 0.2.3
Description The issue allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources due to improper wrapping of the cupsGetFile and cupsPutFile function calls. This can lead to a breach of confidentiality and integrity of protected information. The exploitation of this issue can be done remotely.
Recommendations For versions prior to 0.2.3, update to version 0.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to CUPS resources to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01964
CVE-2012-4510
DSA-2562-1
OPENSUSE-SU-2024:10212-1

Produtos afetados

Cups-Pk-Helper