Re: Security hole in hplip

Don <[email protected]> Thu, 03 Feb 2005 08:41:26 -0800
Newsgroups gmane.linux.drivers.hpofficejet.devel
Message-ID <[email protected]>
Erwan David wrote:
> 	On my debian, the .hplip.conf file is created world
> writable. This allows a user A to change B user's printing or
> scanning commands, replacing them with arbitrary commands which will
> run with B's rights.This file should be created in 600 mode.
> 
> 

This will be addressed in version 0.8.8.

Thanks,

Don



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl