16th Apr 2003 [SBWID-6149]
COMMAND
lprng insecure temporary file creation
SYSTEMS AFFECTED
version lprng_3.8.10
PROBLEM
In Debian Security Advisory DSA 285-1 [http://www.debian.org/security/]
:
Karol Lewandowski discovered that psbanner, a printer filter that
creates a PostScript format banner and is part of LPRng, insecurely
creates a temporary file for debugging purpose when it is configured as
filter. The program does not check whether this file already exists or
is linked to another place writes its current environment and called
arguments to the file unconditionally with the user id daemon.
SOLUTION
upgrade to latest version