[Pkg-cups-devel] Bug#623743: Bug#623743: cups-pdf: does not properly set supplementary groups when dropping privileges

Martin-Éric Racine q-funk at iki.fi
Sat Apr 23 09:29:52 UTC 2011


2011/4/22 Christopher Zimmermann <madroach at zakweb.de>:
> Package: cups-pdf
> Version: 2.5.0-16
> Severity: normal
> Tags: upstream patch
>
> When dropping privileges to the user who sent the print job cups-pdf
> does only set euid and egid, but NOT the supplementary groups. Therefore
> a common "print dump" directory only accessible by a "print" group will
> only work when all printing users have a primary group of "print", but
> NOT when it is only a supplementary group.
>
> Patch is attached.

Thanks for this!  Upstream reads the Debian bugs against this package,
so I'll let him comment and decide whether he wants to merge this. In
the meantime, could you check whether this cleanly applies to 2.5.1-2
(currently in unstable, but can easily build for stable, too) and
update the patch as necessary?

Cheers!
Martin-Éric





More information about the Pkg-cups-devel mailing list