cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.
http://www.openwall.com/lists/oss-security/2012/10/12/2
http://www.mandriva.com/security/advisories?name=MDVSA-2013:069