notfound 409356 2.4.2-2 close 409356 2.4.2-2 quit On Mon, Feb 19, 2007 at 10:20:09AM +0100, Klaumi Klingsporn wrote:
> After the permission-change of /usr/lib/backend/cups-pdf in > cups-pdf_2.4.2-2 there is no output in $Home/PDF anymore. > The permissions have to be set to 104754 to get an output: > ls -l /usr/lib/cups/backend/cups-pdf > -rwsr-xr-- 1 root lp 23776 2007-02-14 18:33 > /usr/lib/cups/backend/cups-pdf > I don't think that there is a security hole, because no unprivileged > need to be in the group lp. On my system the execution of the initial > mentioned command: > "/usr/lib/cups/backend/cups-pdf shadow user title 1 '' /etc/shadow" > by an unprivileged user only results in: > "bash: /usr/lib/cups/backend/cups-pdf: Keine Berechtigung" This is a bug in CUPS's goofy plugin security model, not a bug in cups-pdf. It is any case a separate bug from this security bug; reclosing. -- Steve Langasek Give me a lever long enough and a Free OS Debian Developer to set it on, and I can move the world. [EMAIL PROTECTED] http://www.debian.org/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]