[cups.bugs] [MOD] STR #2368: Current setuid() approach of deviced leads to unaccessible devices

Michael Sweet mike at easysw.com
Mon Apr 30 06:51:18 PDT 2007


[STR Closed w/o Resolution]

Sigh...  seteuid() becomes the only UID after a fork. The cups-deviced
check honors the root/non-root permission check done by the scheduler, and
your patch disables that, running all backends as root with the standard
CUPS (and that exposes you to more security risks...)

Will not apply this patch.

Link: http://www.cups.org/str.php?L2368
Version: 1.2.10
Fix Version: Will Not Fix





More information about the cups mailing list