PT-2011-1142 · Hewlett Packard+1 · Libsane-Hpaio+7

Sebastian Krahmer

·

Publicado

2011-01-17

·

Atualizado

2024-06-15

·

CVE-2010-4267

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions hplip versions 1.6.7 through 3.10.9 hplip3-common version 3.9.8 hplip3-libs version 3.9.8 hplip3-gui version 3.9.8 hpijs version 1.6.7 libsane-hpaio version 1.6.7 libsane-hpaio3 version 3.9.8 hplip version 3.9.8
Description The issue is related to a stack-based buffer overflow in the hpmud get pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP), which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For hplip versions 1.6.7 through 3.10.9, consider updating to a version later than 3.11.10. For hplip3-common version 3.9.8, restrict access to the hpmud get pml function until a patch is available. For hplip3-libs version 3.9.8, avoid using the hpmud get pml function in the affected API endpoint until the issue is resolved. For hplip3-gui version 3.9.8, disable the hpmud get pml function as a temporary workaround until a patch is available. For hpijs version 1.6.7, restrict access to the vulnerable module to minimize the risk of exploitation. For libsane-hpaio version 1.6.7, consider disabling the hpmud get pml function until a patch is available. For libsane-hpaio3 version 3.9.8, avoid using the vulnerable parameter in the affected API endpoint until the issue is resolved. For hplip version 3.9.8, update to a version later than 3.11.10 to resolve the issue.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07258
BDU:2015-07259
BDU:2015-07260
BDU:2015-07261
BDU:2015-07262
BDU:2015-07263
BDU:2015-07372
BDU:2015-07373
BDU:2015-08655
BDU:2015-08656
BDU:2015-08657
BDU:2015-08658
BDU:2015-08659
BDU:2015-09433
CVE-2010-4267
DSA-2152-1
OPENSUSE-SU-2024:10083-1
RHSA-2011:0154
RHSA-2011_0154

Produtos afetados

Red Hat
Hpijs
Hplip
Hplip3-Common
Hplip3-Gui
Hplip3-Libs
Libsane-Hpaio
Libsane-Hpaio3