A privilege escalation flaw was found in the way cups, a Common Unix Printing System, performed demarcation of privileges for the members of SystemGroup, different from the privileged-user account (root). A remote attacker, member of some of the CUPS SystemGroup groups, could use this flaw to read / write arbitrary system file with the privileges of the user running the CUPS daemon. References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692791 [2] http://www.openwall.com/lists/oss-security/2012/11/10/5 Upstream bug report: [3] http://www.cups.org/str.php?L4223 (private for now)
*** This bug has been marked as a duplicate of bug 875898 ***