[6277] in bugtraq
Re: Possible Bug in CDE on HP-UX
daemon@ATHENA.MIT.EDU (Jeremy Brinkley)
Tue Mar 10 21:43:25 1998
Date: Tue, 10 Mar 1998 16:25:01 -0800
Reply-To: Jeremy Brinkley <jeremy@WISHBONE.STANFORD.EDU>
From: Jeremy Brinkley <jeremy@WISHBONE.STANFORD.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <Pine.HPP.3.96.980309103416.6297A-100000@hp10.ecs.csun.edu>
On Mon, 9 Mar 1998, gareth greenaway wrote:
> While playing around with CDE on the HP-UX workstations at my university i
> recently discovered a oddity. In the CDE printer mangager I discovered
> that I, using my normal student login, could delete print jobs from the
> print que. Including those that weren't mine. Although this doesnt seem
> like a severe security risk, im sure other users wouldnt be too happy to
> know that someone could easily delete their print jobs.
I'm not sure this is a CDE issue; any user can cancel another user's
print jobs by default on HP-UX. It's on purpose, since the user sitting
next to the garbage-spewing printer may not be the user who submitted the
job. The administrator can override this on a per-printer basis
using the -orc option to lpadmin(1m).
Jeremy Brinkley jeremy@wishbone.stanford.edu
System Administrator finger for PGP key (2.6.2) or
Stanford Blood Center http://wishbone.stanford.edu/~jeremy