PT-2013-1082 · Hewlett Packard+3 · Hplip+3

Raphael Geissert

·

Publicado

2013-03-06

·

Atualizado

2024-06-15

·

CVE-2013-6402

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Linux Imaging and Printing (HPLIP) versions through 3.13.11
Description The issue concerns multiple vulnerabilities in the HPLIP package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the base/pkit.py file in HPLIP is vulnerable to a symlink attack, allowing local users to overwrite arbitrary files via the /tmp/hp-pkservice.log temporary file.
Recommendations For HPLIP versions through 3.13.11, consider restricting access to the base/pkit.py file to prevent exploitation until a patch is available. As a temporary workaround, avoid using the hp-pkservice.log temporary file in the /tmp directory to minimize the risk of arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1475
BDU:2015-02622
CVE-2013-6402
DSA-2829-1
MGASA-2014-0033
OPENSUSE-SU-2024:10083-1

Produtos afetados

Alt Linux
Debian
Hplip
Suse