LPPlus dccscan unprivileged read vulnerability

$LPHOME/bin/dccscan is suid-root and can be executed by any user. It is possible for an unprivileged user to print files to which he does not have read access. In testing, this works even for printers to which the user is is not given any access in the LPPlus security configuration.


 

Privacy Statement
Copyright 2010, SecurityFocus