PT-2011-4873 · Hewlett Packard · Hp Managed Printing Administration

Andrea Micalizzi

+1

·

Publicado

2011-12-22

·

Atualizado

2019-10-09

·

CVE-2011-4167

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP Managed Printing Administration versions prior to 2.6.4
Description The issue is related to a stack-based buffer overflow in the MPAUploader.dll component. This can be exploited by remote attackers to execute arbitrary code via a long filename parameter in an uploadfile action to the "Default.asp" endpoint.
Recommendations For versions prior to 2.6.4, update to version 2.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the MPAUploader.dll component or the "Default.asp" endpoint to minimize the risk of exploitation. Avoid using long filenames in the uploadfile action until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4167
ZDI-11-353

Produtos afetados

Hp Managed Printing Administration