Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-4405

Published: 17 November 2011

The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting database, which allows remote attackers to execute arbitrary code via a man-in-the-middle (MITM) attack that modifies packages or repositories.

Notes

AuthorNote
mdeslaur
fingerprints are only supported on natty+

Priority

High

Status

Package Release Status
system-config-printer
Launchpad, Ubuntu, Debian
hardy Ignored
(end of life)
lucid Not vulnerable

maverick Not vulnerable

natty
Released (1.3.1+20110222-0ubuntu16.5)
oneiric
Released (1.3.6+20110831-0ubuntu9.4)
upstream Needs triage