Security review:
With a shallow code audit, the code seems ok and is quite small. It (obviously) 
ships a dbus system service. The recent fixes for the CVE look ok. Upstream 
reported the issue responsibly, provided patches and was receptive to feedback 
on the patches. The package is a root running application that processes input 
from the user session. It would be good if this had full hardening options 
during compilation. The policykit policy looks ok (note that we ship polkit 
overrides that allow all actions to anyone in the lpadmin, sudo or admin groups 
if they have an active session-- this is ok). The packaging looks fine. It 
looks like there are some test files that could be run (in src/test-*).

Conditional ACK provided we compile with PIE and BIND_NOW and try to get
the testsuite going during build.

** Changed in: cups-pk-helper (Ubuntu)
     Assignee: Jamie Strandboge (jdstrand) => Martin Pitt (pitti)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/808829

Title:
  [MIR] cups-pk-helper

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/808829/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to