Security review:
With a shallow code audit, the code seems ok and is quite small. It (obviously)
ships a dbus system service. The recent fixes for the CVE look ok. Upstream
reported the issue responsibly, provided patches and was receptive to feedback
on the patches. The package is a root running application that processes input
from the user session. It would be good if this had full hardening options
during compilation. The policykit policy looks ok (note that we ship polkit
overrides that allow all actions to anyone in the lpadmin, sudo or admin groups
if they have an active session-- this is ok). The packaging looks fine. It
looks like there are some test files that could be run (in src/test-*).
Conditional ACK provided we compile with PIE and BIND_NOW and try to get
the testsuite going during build.
** Changed in: cups-pk-helper (Ubuntu)
Assignee: Jamie Strandboge (jdstrand) => Martin Pitt (pitti)
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/808829
Title:
[MIR] cups-pk-helper
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/808829/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs