cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cups-pk-helper | Jul 30, 2024 | Nov 20, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 12, 2012 |
| Suse | — | Upgrade cups-pk-helper-langUpgrade system-config-printerUpgrade system-config-printer-langUpgrade cups-pk-helper | Aug 9, 2024 | Nov 28, 2012 |
| Ubuntu | — | Upgrade cups-pk-helper | Nov 19, 2024 | Nov 20, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub