[cups.bugs] Re: [LOW] STR #1434: CUPS sets ownership of /var/spool/cups/tmp to root.nogroup (should be lp.sys)

Michael Sweet mike at easysw.com
Tue Feb 21 13:42:19 PST 2006


[STR Closed w/o Resolution]

Till, this is as designed.  The SystemGroup and Group can no longer map to
the same GIDs for security reasons.  Basically, if they were the same then
any filter or CGI program could authenticate as root without asking for a
password!

65534 (-2) is the classic "nobody" group and is the fallback if the system
sees that SystemGroup and Group share a GID.

The Debian folks have added an "lpadmin" group to use for the SystemGroup,
and you can use the "lp" group for Group - the default configuration
script checks for the available groups...

Link: http://www.cups.org/str.php?L1434
Version: 1.2-current
Fix Version: Will Not Fix





More information about the cups mailing list