Comment 58 for bug 112803

Revision history for this message
Till Kamppeter (till-kamppeter) wrote :

See Mike's comment and my last comment in

http://www.cups.org/str.php?L2438

I have looked into the patches of the Ubuntu CUPS package and the relevant patch (8 KB) is attached. The patch separates the verification of the credentials into an external program which runs SUID root (as CUPS runs as user in Ubuntu). Username and password are sent via a pipe to the standard input of the external program (newly introduced function "cupsdCallPamAuthHelper()"). It seems that this pipe is not correctly closed.

The patch is one of Martin Pitt's non-root mode patches, therefore assigning to Martin Pitt.